20236 Commits

Author SHA1 Message Date
Mathieu Tortuyaux
024fc45aa0
Merge pull request #3082 from flatcar/linux-6.6.96-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.95 to 6.6.96
2025-07-10 09:17:08 +02:00
Flatcar Buildbot
d08feee3ad
sys-kernel/coreos-sources: Update from 6.6.95 to 6.6.96 2025-07-10 09:16:44 +02:00
Flatcar Buildbot
d9f98a81fb app-misc/ca-certificates: Update from 3.113 to 3.113.1 2025-07-07 07:12:50 +00:00
Krzesimir Nowak
de19afb902 overlay app-admin/sudo: Keep /etc/sudoers.d directory
It seems to be randomly kept or removed during installation, and we
need the directory when creating the SDK container.
2025-07-01 13:40:04 +02:00
Sayan Chowdhury
6605a25cc8 app-admin/sudo: Apply Flatcar patches
- Remove Perl Runtime Dependency
- Remove OpenLDAP schema files for sudo
- Remove sudo.conf file as it is shipped via baselayout

Signed-off-by: Sayan Chowdhury <schowdhury@microsoft.com>
2025-07-01 13:39:58 +02:00
Krzesimir Nowak
0e8f2ca6bb app-admin/sudo: Sync with Gentoo
It's from Gentoo commit 45a501b67600b00178fb68ce2bf8b8516eb28cc5.
2025-07-01 13:39:46 +02:00
Robin Schneider
82cba72c0c
OEM: Provide STACKIT images 2025-06-30 17:46:52 +02:00
Flatcar Buildbot
7879bd4fc1
sys-kernel/coreos-sources: Update from 6.6.94 to 6.6.95 2025-06-30 16:58:14 +02:00
Flatcar Buildbot
12a34c1937 app-misc/ca-certificates: Update from 3.112 to 3.113 2025-06-23 07:11:36 +00:00
Flatcar Buildbot
e10f1e6e64 sys-kernel/coreos-sources: Update from 6.6.93 to 6.6.94 2025-06-20 07:07:01 +00:00
Flatcar Buildbot
d7b3171f89 sys-kernel/coreos-sources: Update from 6.6.92 to 6.6.93 2025-06-05 07:07:02 +00:00
Flatcar Buildbot
1a0b3e385f app-misc/ca-certificates: Update from 3.111 to 3.112 2025-06-02 07:11:32 +00:00
Flatcar Buildbot
551c24ff8b sys-kernel/coreos-sources: Update from 6.6.91 to 6.6.92 2025-05-23 07:07:34 +00:00
Mathieu Tortuyaux
580e5d9082
profiles: enable JSON support for nftables
This help for automation and scripting purposes. dev-libs/jansson is
already shipped in the generic image.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2025-05-22 17:20:12 +02:00
Flatcar Buildbot
f67448bc5c sys-kernel/coreos-sources: Update from 6.6.90 to 6.6.91 2025-05-18 07:05:51 +00:00
Mathieu Tortuyaux
86fcc0c276
Merge pull request #2891 from flatcar/linux-6.6.90-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.89 to 6.6.90
2025-05-15 15:46:32 +02:00
Flatcar Buildbot
5d9ece6f3b
sys-kernel/coreos-sources: Update from 6.6.89 to 6.6.90 2025-05-15 15:46:09 +02:00
Mathieu Tortuyaux
fc9f42dd30
coreos-base/misc-files: add back BCC tools
This file was not sourced because it does not have '.bash' or '.sh'
suffix.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2025-05-12 17:36:15 +02:00
Flatcar Buildbot
07fbfc776c app-misc/ca-certificates: Update from 3.110 to 3.111 2025-05-12 07:11:26 +00:00
Flatcar Buildbot
45fa6b8a5e sys-kernel/coreos-sources: Update from 6.6.88 to 6.6.89 2025-05-02 07:05:36 +00:00
Flatcar Buildbot
63ada836ef sys-kernel/coreos-sources: Update from 6.6.87 to 6.6.88 2025-04-26 07:05:33 +00:00
Flatcar Buildbot
edfd9f0c11 sys-kernel/coreos-sources: Update from 6.6.84 to 6.6.87 2025-04-11 07:06:08 +00:00
Flatcar Buildbot
5125be8d81 app-misc/ca-certificates: Update from 3.109 to 3.110 2025-03-31 07:11:09 +00:00
Mathieu Tortuyaux
539ce40c25
Merge pull request #2762 from flatcar/linux-6.6.84-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.83 to 6.6.84
2025-03-27 09:29:37 +01:00
Mathieu Tortuyaux
f0e55a7f51
sys-kernel/coreos-sources: update revert pahole patch
Follow-up from: 5daa0c35a1

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2025-03-26 13:34:42 +01:00
James Le Cuirot
8dd76ab856
sys-kernel/bootengine: Bump to address Ignition mount issue on PXE
Signed-off-by: James Le Cuirot <jlecuirot@microsoft.com>
2025-03-24 10:08:10 +00:00
Flatcar Buildbot
f778d887bd sys-kernel/coreos-sources: Update from 6.6.83 to 6.6.84 2025-03-23 07:05:00 +00:00
Flatcar Buildbot
9a96085a44 sys-kernel/coreos-sources: Update from 6.6.82 to 6.6.83 2025-03-14 17:28:01 +00:00
Jeremi Piotrowski
d355ecf1da nvidia-drivers: Split amd64 and arm64 driver version
The R535 driver branch, which is LTS, does not compile on arm64 with GCC
14/kernel 6.6. Keep amd64 on R535 and switch arm64 to R570 by default.
R570 is the first driver version that I found that is currently
supported and works for arm64.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
5d4b6697c9 setup-nvidia: Overlay host /lib/modules into devcontainer
So that we can pick-up kmods contained in sysexts (like zfs) and generate
complete module dependency information. I thought we could skip running depmod
for nvidia drivers because we manually insmod them, but nvidia's GPU operator
driver validation expects to be able to run modprobe - so we have to generate
them.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
ab519ab4d2 setup-nvidia: Keep systemd unit when running nspawn container
The nspawn container runs in it's own scope, which journal output is then
associated with. By passing `--keep-unit` we can guarantee that all log output
will stay associated with the nvidia.service and can be viewed by running
`journalctl -u nvidia.service`.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
066fb3ffd4 install-nvidia: Force building proprietary kernel module
Installers for 570 sometimes default to Open drivers, which we can't support
properly at this time. Force proprietary drivers. There are also additional
options that suppress certain worrisome error strings - enable those if
supported too.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
6a92c7cce8 coreos-modules: Cross-compile module build tools
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
2381ea1f99 setup-nvidia: Keep devcontainer image sparse
This saves space at runtime.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
418f26ae6b setup-nvidia: Make "current" symlink logic more robust
Users have reported that in some cases the nvidia.service fails because
/opt/nvidia/current is a directory and the symbolic link gets created inside
it. I have no idea how we get there, but to make the service robust in the face
of this kind of issue:

- remove the directory if it exists
- use `-T` with ln to ensure that symbolic link creation fails if `current` is a directory

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Jeremi Piotrowski
b2c608769d setup-nvidia: Support aarch64 installer
Use `uname -m` to fetch the correct driver installer for aarch64 or x86_64.

Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-03-14 10:59:01 +01:00
Mathieu Tortuyaux
d217f41e4c
Merge pull request #2734 from flatcar/linux-6.6.82-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.80 to 6.6.82
2025-03-12 14:19:44 +01:00
Mathieu Tortuyaux
ccadf0ad2f
coreos-base/coreos-init: add EGIT_BRANCH
As we are using the `git` eclass, we can't simply use a git ref if this
one is on another branch, we need to pass the git branch as well.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2025-03-11 13:12:51 +01:00
Dongsu Park
3274a186a8 overlay coreos-init: Distribute new sub key 2025
This pulls in https://github.com/flatcar/init/pull/129
to distribute the new sub key.
2025-03-10 16:14:50 +01:00
Flatcar Buildbot
9a72d4cac2 sys-kernel/coreos-sources: Update from 6.6.80 to 6.6.82 2025-03-10 07:09:46 +00:00
Thilo Fromm
48a59a2d25 coreos-modules: move mana kmod to commonconfig
This change moves CONFIG_MICROSOFT_MANA=m from amd64_defconfig-6.6 to
commonconfig-6.6 to support the MANA network driver on ARM64 instances,
too.

Signed-off-by: Thilo Fromm <thilofromm@microsoft.com>
2025-03-07 16:48:18 +01:00
Mathieu Tortuyaux
c656eb4185
Merge pull request #2704 from flatcar/linux-6.6.80-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.79 to 6.6.80
2025-03-03 09:29:02 +01:00
Flatcar Buildbot
8a04261a81 app-misc/ca-certificates: Update from 3.108 to 3.109 2025-03-03 07:09:57 +00:00
Dongsu Park
c37d8592cd overlay wa-linux-agent: apply patch to fix ssh public key override issue
Apply patch to fix an issue when overriding ssh public key from ignition
configuration. Since the fix is not available in releases of
wa-linux-agent, we should apply a separate patch.

See also https://github.com/Azure/WALinuxAgent/pull/3309.
2025-02-28 15:14:11 +01:00
Flatcar Buildbot
7a114a06d8 sys-kernel/coreos-sources: Update from 6.6.79 to 6.6.80 2025-02-28 07:06:03 +00:00
Mathieu Tortuyaux
05636ea59c
Merge pull request #2681 from flatcar/linux-6.6.79-flatcar-4230
Upgrade Linux Kernel for flatcar-4230 from 6.6.78 to 6.6.79
2025-02-25 09:24:21 +01:00
Jeremi Piotrowski
1fbed222a6 app-misc/ca-certificates: Account for certs missing newlines
Concatenating certificates missing newlines naively with cat results in broken
bundle. Fix the issue by using a sed expression that appends a trailing newline
after the lastline if it is missing.

Issue: flatcar/flatcar#1601
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2025-02-24 17:07:11 +01:00
Flatcar Buildbot
6849bd5dd8 sys-kernel/coreos-sources: Update from 6.6.78 to 6.6.79 2025-02-22 07:05:52 +00:00
Mathieu Tortuyaux
3b19bdfc08
net-misc/openssh: apply Qualys patch
this fix DOS and MITM vulnerabilities.

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2025-02-20 17:19:26 +05:30
Flatcar Buildbot
f6c0719c57 sys-kernel/coreos-sources: Update from 6.6.77 to 6.6.78 2025-02-18 07:05:14 +00:00