openSUSE_Backports_SLE-16.0_PullRequest_2449__patchinfo.20260625143306023502.93181000773252 Recommended update for shadowsocks-rust moderate openSUSE Backports SLE-16.0 PullRequest 2449 This update for shadowsocks-rust fixes the following issues: Changes in shadowsocks-rust: - Comprehensive systemd service hardening (bnc#1212862 and boo#1263916) * Add CAP_DAC_READ_SEARCH to AmbientCapabilities/CapabilityBoundingSet to allow reading certificates from restricted dynamic paths. * Ensures v2ray-plugin can access Let's Encrypt keys reliably. * Restrict root powers using CapabilityBoundingSet (minimal privileges). * Isolate filesystem via ProtectSystem=full and ProtectHome=true. * Whitelist binary and config access with ReadOnlyPaths. * Disable kernel/device modifications (ProtectKernel*, PrivateDevices). * Introduce SELinux and AppArmor as optional security hardening schemes, and add shadowsocks-libev-selinux and shadowsocks-libev-apparmory subpackages. - Integrate shadowsocks-sysuser for proper non-privileged user handling (boo#1264355). - Run ssserver with root privileges to allow binding to privileged ports and reading SSL certificates (boo#1263916) - Fix shadowsocks-rust-client.service uses Type=forking but sslocal is not a forking daemon (boo#1256041) - Update version to 1.24.0 * Support logging to file and syslog * HTTP Client support auto retry if cached connection was lost * Fix bugs - Update version to 1.23.5 * Updated once_cell::sync::Lazy to std::sync::LazyLock * ACL supported outbound_allow_list * Allow customizable SocketProtect trait for Android VpnService * Fix bugs - Update version to 1.23.4 * online-config: SIP008 online configuration supports adding plugin whitelist (see README for details) * Fix bugs - Update version to 1.23.2 * local-tun: Fixes panic when resizing cached buffers * local-tun: Enable congestion control algorithm for TCP connections * local-tun: Disable TCP package receive checksum for improving performance * local-tun: Buffer for receiving/sending packets from/to tun device are cached globally * Fix some issues - Update version to 1.23.0 * local-fake-dns switched storage engine from sled to rocksdb, users should delete the old database file and let sslocal recreate it ageain * refactor: change error handling to be strongly-typed * fix: mips-* reenabled, moka automatically switches to a fallback impl for AtomicU64 - Fix start failure by systemd * Make sure /etc/shadowsocks can be read by shadowsocks user * Create the PID file under /run/shadowsocks - Update version to 1.21.2 * supports generic I/O socket type * Support OpenBSD Packet-Filter (pf) * Fix bugs shadowsocks-rust-1.24.0-bp160.999999.1.1.src.rpm shadowsocks-rust-1.24.0-bp160.999999.1.1.x86_64.rpm shadowsocks-rust-apparmor-1.24.0-bp160.999999.1.1.noarch.rpm shadowsocks-rust-debuginfo-1.24.0-bp160.999999.1.1.x86_64.rpm shadowsocks-rust-debugsource-1.24.0-bp160.999999.1.1.x86_64.rpm shadowsocks-rust-selinux-1.24.0-bp160.999999.1.1.noarch.rpm shadowsocks-rust-1.24.0-bp160.999999.1.1.s390x.rpm shadowsocks-rust-debuginfo-1.24.0-bp160.999999.1.1.s390x.rpm shadowsocks-rust-debugsource-1.24.0-bp160.999999.1.1.s390x.rpm shadowsocks-rust-1.24.0-bp160.999999.1.1.ppc64le.rpm shadowsocks-rust-debuginfo-1.24.0-bp160.999999.1.1.ppc64le.rpm shadowsocks-rust-debugsource-1.24.0-bp160.999999.1.1.ppc64le.rpm shadowsocks-rust-1.24.0-bp160.999999.1.1.aarch64.rpm shadowsocks-rust-debuginfo-1.24.0-bp160.999999.1.1.aarch64.rpm shadowsocks-rust-debugsource-1.24.0-bp160.999999.1.1.aarch64.rpm