David Michael
b7bdea6375
Merge pull request #2434 from dm0-/glsa
...
Fix some recent GLSAs
2017-02-21 15:13:32 -08:00
David Michael
a09f1082f9
profiles: sync tcpdump
2017-02-21 15:05:07 -08:00
David Michael
938a84e994
Merge pull request #2430 from dm0-/glsa-glibc
...
Update to glibc 2.23
2017-02-21 15:03:07 -08:00
Euan Kemp
9b9137caeb
app-emulation/docker: update runc dependency
...
See previous commit for more info on the re-versioning
2017-02-21 11:08:29 -08:00
Euan Kemp
872961ff35
app-emulation/runc: update to use intended version
...
This updates the ebuild to include a patch number indicating changes
since the referenced version number.
This is because docker uses untagged versions of runc, and so we need
additional version information.
Prior to this change, the runc ebuild inadvertently used the upstream
distfile cache of runc's distfile, regardless of the commit referenced
and the -r bumps.
This also re-fixes CVE-2016-9962. The patch for that vulnerability was
dropped once we thought the commit contained the fix, but since the
commit was being ignored and the fix never made it into any tagged
release, we accidentally regressed.
Finally, tihs updates the selinux patch. This was sourced from
projectatomic/runc on the docker-1.13.1 branch.
2017-02-21 11:07:31 -08:00
David Michael
a0014ac5d4
app-emulation/rkt: bump to 1.25
2017-02-20 16:26:49 -08:00
David Michael
0c2357d106
sys-libs/glibc: apply CoreOS changes
2017-02-19 17:40:00 -08:00
David Michael
c4cd8102e5
sys-libs/glibc: sync with upstream to version 2.23
2017-02-19 16:08:26 -08:00
Euan Kemp
5e261ead8d
app-emulation/runc: show commit hash in --version
2017-02-17 17:10:03 -08:00
Benjamin Gilbert
5428687181
sys-kernel/bootengine: fix root directory mode 1777 on tmpfs
2017-02-17 12:42:58 -08:00
Benjamin Gilbert
e675857a8c
Merge pull request #2426 from bgilbert/kernel-revbump
...
sys-kernel/coreos-sources: Add script to revbump and update patches
2017-02-16 12:29:43 -08:00
Benjamin Gilbert
6f49ad8f9f
Merge pull request #2414 from sherter/urxvt-256color
...
sys-libs/ncurses: add rxvt-unicode-256color
2017-02-16 12:29:17 -08:00
Simon Herter
8cf857f23e
sys-libs/ncurses: add rxvt-unicode-256color
2017-02-16 11:49:53 +01:00
Benjamin Gilbert
c40a789795
sys-kernel/coreos-sources: Add script to revbump and update patches
2017-02-15 13:08:40 -08:00
David Michael
e9a8442351
Merge pull request #2424 from dm0-/glsa
...
Fix the OpenSSL GLSA
2017-02-14 13:39:37 -08:00
David Michael
355d0dc88c
Merge pull request #2418 from dm0-/docker
...
Upgrade to Docker 1.13.1
2017-02-14 13:26:29 -08:00
David Michael
5b487075b9
Merge pull request #2425 from dm0-/bugs-1807
...
sys-apps/shadow: do not link nonexistent files
2017-02-14 13:24:17 -08:00
David Michael
3fe151f094
sys-apps/shadow: do not link nonexistent files
2017-02-14 13:05:10 -08:00
Benjamin Gilbert
58fd27ad2e
Merge pull request #2423 from bgilbert/kernel-4.9.9
...
sys-kernel/coreos-*: Bump to 4.9.9
2017-02-14 13:02:34 -08:00
David Michael
10c2b11e24
dev-libs/openssl: apply CoreOS changes
...
Specifically, stabilize the arm64 version, drop pkg_postinst, and
remove the bindist USE flag.
2017-02-14 12:33:13 -08:00
David Michael
b753c741a4
dev-libs/openssl: bump to 1.0.2k
...
Addresses CVE-2016-7055, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732.
2017-02-14 12:33:09 -08:00
Benjamin Gilbert
919578496b
sys-kernel/coreos-kernel: bump to v4.9.9
2017-02-14 11:20:05 -08:00
Benjamin Gilbert
8232dd1155
sys-kernel/coreos-modules: bump to v4.9.9
2017-02-14 11:20:05 -08:00
Benjamin Gilbert
faf25d6dd9
sys-kernel/coreos-sources: bump to v4.9.9
2017-02-14 11:20:01 -08:00
David Michael
997a1b6e94
sys-apps/shadow: load defaults from the chroot
2017-02-13 11:58:35 -08:00
David Michael
f8a473962b
app-emulation/docker: upgrade to unpatched 1.13.1
2017-02-08 18:20:03 -08:00
David Michael
3b11b06960
app-emulation/containerd: sync with Docker 1.13.1 commits
2017-02-08 18:16:57 -08:00
David Michael
e3866ddc98
app-emulation/runc: sync with Docker 1.13.1 commits
2017-02-08 18:15:00 -08:00
Benjamin Gilbert
2c93229944
sys-kernel/coreos-sources: Stop routing primary console to ttyS0
...
Our GRUB config specifies tty0 as the primary console, but it was being
forced to the serial port instead. As a result, boot failures produced
no visible error messages on tty0, and the emergency shell was likewise
inaccessible.
2017-02-07 13:27:05 -08:00
David Michael
68064fdbf8
chore(metadata): Regenerate cache
2017-02-06 10:52:27 -08:00
David Michael
aeb2c71a3b
dev-util/ccache: move back to portage-stable
2017-02-06 10:52:20 -08:00
Alex Crawford
6c714105c5
coreos-base/oem-azure: bump to v2.2.4
2017-02-03 13:16:38 -08:00
Alex Crawford
43cff3c3f4
app-emulation/wa-linux-agent: bump to v2.2.4
2017-02-03 12:57:19 -08:00
Scott Burns
27000b8fa5
coreos-overlay/oem-packet: Remove bond workaround
...
Now that Packet uses Ignition to configure systemd-networkd units
before systemd-networkd starts, the workaround described in the
below issue is no longer necessary:
https://github.com/coreos/bugs/issues/36
2017-02-02 23:16:05 -08:00
Euan Kemp
ca08f9797b
app-emulation/docker: upgrade to coreos-1.13.0
2017-02-02 23:04:34 -08:00
Alex Crawford
0ef1b76779
Merge pull request #2410 from crawford/cpus
...
sys-kernel/coreos-kernel: increase CONFIG_NR_CPUS
2017-02-01 18:06:32 -08:00
jakub-d
e423581c75
sys-kernel/coreos-kernel: increase CONFIG_NR_CPUS
2017-02-01 15:47:38 -08:00
David Michael
e0a8e7a82e
Merge pull request #2408 from dm0-/glsa
...
GLSA syncs
2017-02-01 14:11:29 -08:00
David Michael
8f190facd2
profiles: sync squashfs and libpng versions on arm64
2017-02-01 12:00:57 -08:00
Euan Kemp
f324f1c7c5
Revert "Merge pull request #2403 from euank/1298-runc-userns"
...
This reverts commit 7f3b121e061d4592729161026f18abe5444f22f0, reversing
changes made to aaaef8fa392528e6b57135a960428e9ef8b0dfbc.
I messed up and cherry-picked into master instead of the build-1298
branch and it worked because the file in question had since been renamed
to rc4.
This reverts that extraneous file.
2017-01-31 22:44:04 -08:00
David Michael
08200dc94a
Merge pull request #2404 from dm0-/bugs-1773
...
Upgrade to OpenSSH 7.4_p1
2017-01-31 20:17:24 -08:00
Euan Kemp
85cd5d0426
Merge pull request #2403 from euank/1298-runc-userns
...
app-emulation/runc: workaround userns issue
2017-01-31 19:38:24 -08:00
David Michael
681c94dc41
net-misc/openssh: apply our changes to the new version
...
Specifically, this drops the bindist USE flag, skips installing
some init.d files, and updates KEYWORDS for our architectures.
The build fix carried previously has been dropped since it is now
included in the upstream source archive.
2017-01-31 18:15:09 -08:00
David Michael
1d4139c1f0
net-misc/openssh: sync with the latest Gentoo ebuild
2017-01-31 18:15:09 -08:00
Euan Kemp
af7423451f
app-emulation/runc: workaround userns issue
...
This fixes a bug in usernamespace support under selinux.
This patch matches the one applied to fedora.
2017-01-31 17:22:40 -08:00
David Michael
1275e42126
app-emulation/containerd: sync with Docker 1.13 commits
2017-01-31 13:56:04 -08:00
David Michael
b1db1b1b9f
app-emulation/docker-proxy: sync with Docker 1.13 commits
2017-01-31 13:56:04 -08:00
David Michael
c13e3b9294
app-emulation/runc: sync with Docker 1.13 commits
2017-01-31 13:56:04 -08:00
Euan Kemp
57351ee715
Merge pull request #2399 from euank/selinux-userns-backport
...
sys-kernel/coreos-sources: backport selinux+userns patch
2017-01-30 18:15:40 -08:00
Euan Kemp
07f1c9d7f6
app-emulation/runc: workaround userns issue
...
This fixes a bug in usernamespace support under selinux.
This patch matches the one applied to fedora.
2017-01-30 17:39:45 -08:00