Dongsu Park
a76fb38501
Merge pull request #1120 from kinvolk/dongsu/containerd-1.5.4
...
app-emulation/containerd: update to 1.5.4
2021-07-20 16:49:08 +02:00
Dongsu Park
70bfaff439
app-emulation/containerd: update to 1.5.4
...
Update app-emulation/containerd to 1.5.4, mainly to address
CVE-2021-32760.
2021-07-20 16:36:48 +02:00
Dongsu Park
2df538b480
Merge pull request #1115 from kinvolk/go-1.16.6-main
...
Upgrade Go in main from 1.16.5 to 1.16.6
2021-07-19 18:28:20 +02:00
Jeremi Piotrowski
0a1b0be7f3
dev-lang/rust: don't enable aarch64 cross target when host is aarch64
...
This does not work because the host and cross rust targets share the
same name. This needs to be reworked to (potentially) enable x86 cross
targets for aarch64 targets.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:09:01 +00:00
Jeremi Piotrowski
0064e6b3ec
profiles: remove "pc xen" from arm64 GRUB_PLATFORMS
...
grub refuses to build these targets when host is arm64.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:08:59 +00:00
Jeremi Piotrowski
a90c4265bf
profiles: move BOOSTRAP_USE=cros_host to arch indepenent part of sdk profile
...
So that it can apply to both arm64 and amd64 sdk profiles.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:08:56 +00:00
Jeremi Piotrowski
d460bf3a8d
coreos-base/update_engine: add glib-utils to (B)DEPEND
...
glib-utils are used during the build so they need to be part of host
dependencies for update_engine. This only really pops up during a repeat
bootstrap, when update_engine is being built from source but glib has
been installed from a binary. BDEPEND would be the correct variable but
that requires EAPI=7, so additionally added it to DEPEND for now.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:08:54 +00:00
Jeremi Piotrowski
44fcb0513a
mark platform specific host/sdk dependencies as amd64/!arm64
...
kola-data and google-cloud-sdk install pre-built amd64 binaries, so
there's no point installing them right now. Both could be made to work
at a later time. iucode and syslinux and are x86 specific and won't
build. selinux related packages *currently* don't work/build on arm64
but could be made to work.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:08:51 +00:00
Jeremi Piotrowski
0aaa9766c7
keyword sdk dependencies for arm64
...
Where the packages are part of coreos-overlay, I keyworded the ebuilds
directly to the same level of stability as amd64. Other packages have
been keyworded through the profile, as close to the amd64 level as I
could manage.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-19 15:08:48 +00:00
Dongsu Park
065661a751
Merge pull request #1113 from kinvolk/dongsu/open-vm-tools-11.3.0
...
app-emulation/open-vm-tools: update to 11.3.0
2021-07-19 12:01:03 +02:00
Flatcar Buildbot
e03a28561c
dev-lang: Upgrade Go 1.16.5 to 1.16.6
2021-07-19 07:26:12 +00:00
Mathieu Tortuyaux
abd1e615c0
Merge pull request #1112 from kinvolk/containerd-1.5.3-main
...
Upgrade Containerd in main from 1.5.2 to 1.5.3
2021-07-16 15:52:27 +02:00
Jeremi Piotrowski
23d3861740
Merge pull request #1105 from kinvolk/sayan+jepio/update-dracut
...
Sayan+jepio/update dracut
Closes kinvolk/Flatcar#375
2021-07-16 15:47:17 +02:00
Dongsu Park
688eed80f3
coreos-base/oem-vmware: update to 11.3.0
...
Update oem-vmware to 11.3.0, corresponding to the update of
open-vm-tools to 11.3.0.
2021-07-16 13:54:28 +02:00
Dongsu Park
53983eb353
app-emulation/open-vm-tools: update to 11.3.0
...
Update open-vm-tools 11.3.0,
https://github.com/vmware/open-vm-tools/releases/tag/stable-11.3.0 .
Update also the build number to 18090558.
2021-07-16 13:53:51 +02:00
Mathieu Tortuyaux
aa3ad05497
Merge pull request #1048 from kinvolk/tormath1/selinux
...
selinux: upgrade selinux libs
2021-07-16 11:25:10 +02:00
Flatcar Buildbot
4309eaab99
app-emulation: Upgrade Containerd 1.5.2 to 1.5.3
2021-07-16 08:10:14 +00:00
Mathieu Tortuyaux
6841de885a
Revert "app-emulation/docker: disable SELinux"
...
This reverts commit 956f9757d45b7df260ed0e78213e1ad96c7409eb.
2021-07-16 10:04:03 +02:00
Sayan Chowdhury
2a3a1c8bc8
sys-apps/dbus: Apply Flatcar patches
...
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
2021-07-16 10:04:02 +02:00
Sayan Chowdhury
d3d56cda69
sys-apps/dbus: Sync with Gentoo upstream
...
Updates to dbus-1.12.20-r1
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
8bd2eefc3f
app-admin/setools: remove package
...
from 4.x setools is a pure python script, we won't include it
in Flatcar anymore
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
d86d08d640
profiles/coreos/amd64: enable selinux for runc
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
c56eec4bb4
eclass: move selinux-policy-2 to ::portage-stable
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
0ead201568
sec-policy/selinux-unconfined: sync with upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
e2afa149cb
sec-policy/selinux-virt: apply flatcar changes
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:02 +02:00
Mathieu Tortuyaux
e02947a905
sec-policy/selinux-virt: sync with upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:01 +02:00
Mathieu Tortuyaux
4d6ff7cfca
sec-policy/selinux-base-policy: flatcar changes
...
- run sshd (and child) as unconfined_t
- add init.patch to allow execute_no_trans,map and
exec from init to unconfined
- add AVC patch for local login and journald
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:04:01 +02:00
Mathieu Tortuyaux
d819e2afa4
sec-policy/selinux-base-policy: sync with upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:03:10 +02:00
Mathieu Tortuyaux
e472af562e
sec-policy/selinux-base: apply flatcar changes
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-16 10:03:10 +02:00
Jeremi Piotrowski
743f86d4da
sys-kernel/coreos-kernel: strip ROOT from TMPDIR before running dracut
...
Update-bootengine chroots into the sysroot and runs dracut from there.
Dracut 053 has revised TMPDIR handling and the portage TMPDIR prefixed
with ROOT leaks into the chroot. This causes dracut to abort during
setup with the error message "invalid tmpdir".
Override TMPDIR before running update-bootengine to allow dracut to
function.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-15 13:40:50 +00:00
Jeremi Piotrowski
68f2867457
sys-kernel/dracut: Apply Flatcar patches to 053
...
Flatcar uses custom networking scripts in initramfs, so the dracut iscsi
module needs to be patched to account for that.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-07-15 13:40:50 +00:00
Sayan Chowdhury
033048444f
sys-kernel/dracut: Apply Flatcar patches
...
Add Flatcar specific patch to enable the iscsi module
Flatcar uses its own network module instead of the Dracut one, but the
iscsi module depends on the network. So, in order to enable the iscsi
module, we need to patch the dependency
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
2021-07-15 13:40:50 +00:00
Sayan Chowdhury
2a19f3cd76
sys-kernel/dracut: Sync with Gentoo upstream
...
Signed-off-by: Sayan Chowdhury <sayan@kinvolk.io>
2021-07-15 13:40:50 +00:00
Sayan Chowdhury
3f857f9f2a
Merge pull request #1099 from peanutduck/ticket_361
...
net-misc/curl: enable telnet protocol support
2021-07-15 13:11:59 +05:30
Dongsu Park
6c0742bf07
Merge pull request #932 from kinvolk/dongsu/wget-ssl
...
profiles: force to use ssl USE flag for wget
2021-07-15 09:39:41 +02:00
Sayan Chowdhury
31ce217f6a
Merge pull request #1104 from kinvolk/linux-5.10.49-main
...
Upgrade Linux Kernel in main from 5.10.46 to 5.10.49
2021-07-15 10:55:24 +05:30
Jeremi Piotrowski
40328de04b
Merge pull request #929 from wernerb/add-mdio-bcm
...
Enable MDIO_BCM_UNIMAC for arm64
2021-07-13 09:58:28 +02:00
Flatcar Buildbot
70cb0ed335
sys-kernel: Upgrade Kernel 5.10.46 to 5.10.49
2021-07-12 07:15:21 +00:00
peanutduck
b1fa2b24ee
net-misc/curl: enable telnet protocol support
...
Add telnet useflag directly in the package.use file
2021-07-08 23:10:12 +08:00
Mathieu Tortuyaux
92bc08519c
Merge pull request #1093 from kinvolk/tormath1/libgcrypt-1.9.3
...
profiles: accept ~amd64 & ~arm64 for libgcrypt-1.9.3
2021-07-08 09:47:59 +02:00
Mathieu Tortuyaux
fe107d3408
profiles: accept ~amd64 & ~arm64 for libgcrypt-1.9.3
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-08 09:45:07 +02:00
Kai Lüke
e7a0579a7a
Merge pull request #1091 from kinvolk/kai/azure-device-unit
...
coreos-base/coreos-init: add udev systemd tag for Azure storage devices
2021-07-07 12:28:05 +02:00
Kai Lüke
c2b0b0cc7e
coreos-base/coreos-init: add udev systemd tag for Azure storage devices
...
This pulls in
https://github.com/kinvolk/init/pull/41
2021-07-07 12:25:46 +02:00
Mathieu Tortuyaux
1219a8ff35
sec-policy/selinux-base: sync with the upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
b7419c3548
sys-libs/libsemanage: apply flatcar changes
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
5738da828c
sys-libs/libsemanage: sync with the upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
522387fa10
sys-libs/libselinux: apply flatcar changes
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
9aecd8fc33
sys-libs/libselinux: sync with upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
a693d478e1
sys-apps/policycoreutils: apply flatcar changes
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:28 +02:00
Mathieu Tortuyaux
c172da732c
sys-apps/policycoreutils: sync with upstream
...
Signed-off-by: Mathieu Tortuyaux <mathieu@kinvolk.io>
2021-07-06 15:57:27 +02:00