34806 Commits

Author SHA1 Message Date
Krzesimir Nowak
6b94a5eefc sec-policy/selinux-kdump: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
0a8d6375dd sec-policy/selinux-gpg: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
8b0d493ade sec-policy/selinux-git: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
b404308efe sec-policy/selinux-dracut: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
c781e4253a sec-policy/selinux-docker: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
17f5c182bd sec-policy/selinux-dnsmasq: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
4b49bf26a8 sec-policy/selinux-dirmngr: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
4574dafb4e sec-policy/selinux-chronyd: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
9232dc9884 sec-policy/selinux-cdrecord: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
1ab29a18b4 sec-policy/selinux-brctl: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
86d192284e sec-policy/selinux-bind: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
4d2b3f679f sec-policy/selinux-apm: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
fba498d743 sec-policy/selinux-apache: Add from Gentoo
It's from Gentoo commit 0868350882899927dd40131021bfcf8bd117e77c.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
1ce1c96b6a overlay profiles: Switch to hardened/selinux/systemd profiles
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
98fc61013a overlay coreos/config, profiles: Drop PKG_INSTALL_MASK
PKG_INSTALL_MASK is for binary packages like INSTALL_MASK is for
${ROOT} - whatever is added to PKG_INSTALL_MASK will be absent from
binary packages. But we may want to install different content to
different kind of images using the same binary packages. For example,
we may want to install some python selinux scripts to developer
container, but not to production image.

I started adding PKG_INSTALL_MASK before, because of a
misunderstanding - I thought that PKG_INSTALL_MASK is about filtering
files that are installed to ${ROOT} from binary packages. So in
reality, PKG_INSTALL_MASK is really unnecessary.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
Krzesimir Nowak
320145c21f save logs
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-20 15:12:08 +01:00
flatcar-ci
d380460e85 New version: main-4643.0.0-nightly-20260318-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
main-4643.0.0-nightly-20260318-2100
2026-03-18 21:00:27 +00:00
Mathieu Tortuyaux
49c4b396bb
Merge pull request #3461 from flatcar/tormath1/amd-gpu 2026-03-18 13:39:31 +01:00
Mathieu Tortuyaux
a47141174b
Merge pull request #3842 from flatcar/mantle-update-main
Upgrade mantle container image to latest HEAD in main
2026-03-18 13:00:11 +01:00
Flatcar Buildbot
3de3d05cf5 Update mantle container image to latest HEAD
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-18 11:24:40 +00:00
James Le Cuirot
8c35db1f29
Merge pull request #3837 from flatcar/chewi/aci-1.4.2
app-containers/accelerated-container-image: Version bump to 1.4.2
2026-03-18 11:24:25 +00:00
James Le Cuirot
200cf71083
app-containers/accelerated-container-image: Version bump to 1.4.2
Signed-off-by: James Le Cuirot <jlecuirot@microsoft.com>
2026-03-18 11:23:51 +00:00
Mathieu Tortuyaux
dbbbe7a772
sys-kernel/coreos-firmware: ignore some missing firmware
It happens that some modules uses `MODULE_FIRMWARE` with a file
not-shipped into 'linux-firmware'.
In such a case, we can safely ignore those.
e.g 'amdgpu/ip_discovery.bin' is not a file shipped by linux-firmware
(see: a79d3709c4)

Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2026-03-17 13:59:11 +01:00
Mathieu Tortuyaux
2c8cce394c
changelog: add entry
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2026-03-17 13:59:11 +01:00
Mathieu Tortuyaux
bcd1492407
sys-kernel/coreos-modules: build AMD GPU as module
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2026-03-17 13:59:09 +01:00
flatcar-ci
32b025b482 New version: main-4641.0.0-nightly-20260316-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-03-16 21:00:23 +00:00
Mathieu Tortuyaux
55023ce33a
Merge pull request #3834 from flatcar/mantle-update-main
Upgrade mantle container image to latest HEAD in main
2026-03-16 12:36:16 +01:00
Flatcar Buildbot
b14628080f Update mantle container image to latest HEAD
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-16 11:35:14 +00:00
Mathieu Tortuyaux
4c4fe6007f
Merge pull request #3827 from flatcar/linux-6.12.77-main
Upgrade Linux Kernel for main from 6.12.74 to 6.12.77
2026-03-16 12:35:02 +01:00
Mathieu Tortuyaux
7066fe94b9
Merge pull request #3825 from flatcar/firmware-20260309-main
Upgrade Linux Firmware in main from 20260221 to 20260309
2026-03-16 10:05:22 +01:00
Flatcar Buildbot
af108748e6 sys-kernel/coreos-sources: Update from 6.12.74 to 6.12.77
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-14 07:17:02 +00:00
flatcar-ci
ccd09dd929 New version: main-4638.0.0-nightly-20260313-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-03-14 03:01:53 +00:00
flatcar-ci
2b1b7e23e1 New version: main-4638.0.0-nightly-20260313-2100-INTERMEDIATE
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-03-13 21:00:29 +00:00
Krzesimir Nowak
7188460d2b
Merge pull request #3760 from flatcar/buildbot/monthly-glsa-metadata-updates-2026-03-01
Monthly GLSA metadata 2026-03-01
2026-03-13 10:48:37 +01:00
Flatcar Buildbot
d2bba54bba portage-stable/metadata: Monthly GLSA metadata updates
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-13 10:45:04 +01:00
Flatcar Buildbot
e47b1c63aa sys-kernel/coreos-firmware: Update from 20260221 to 20260309
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-12 07:21:20 +00:00
flatcar-ci
992213439e New version: main-4636.0.0-nightly-20260311-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-03-11 21:00:26 +00:00
Mathieu Tortuyaux
5133aacde7
Merge pull request #3821 from flatcar/mantle-update-main
Upgrade mantle container image to latest HEAD in main
2026-03-11 18:36:11 +01:00
Flatcar Buildbot
507a2b7c16 Update mantle container image to latest HEAD
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 17:08:39 +00:00
Krzesimir Nowak
a899f2f97d
Merge pull request #3797 from flatcar/buildbot/weekly-portage-stable-package-updates-2026-03-09
Weekly portage-stable package updates 2026-03-09
2026-03-11 18:08:22 +01:00
Krzesimir Nowak
b3f3561ff4
Merge pull request #3796 from flatcar/krnowak/mask-debuginfod
overlay profiles: Mask USE=debuginfod
2026-03-11 13:11:57 +01:00
Krzesimir Nowak
798635ab8e changelog: Add an entry
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-11 10:10:50 +01:00
Krzesimir Nowak
1c2bf6ee5f overlay sys-boot/shim: Fix building with binutils 2.46
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-11 10:10:50 +01:00
Krzesimir Nowak
025dc54fef overlay profiles: Add accept keywords for binutils
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
3797ce5a7f x11-drivers/nvidia-drivers: Sync with Gentoo
It's from Gentoo commit 5fd3fa3e9bf3ea053703ad48c2a7a0a3fb47dc04.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
14f626b9f7 sys-libs/timezone-data: Sync with Gentoo
It's from Gentoo commit 47523102cc3d5fe863da551a00ebcf98f9aa3e22.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
b673ab1567 sys-libs/pam: Sync with Gentoo
It's from Gentoo commit 106ac09117b3e233440d6780f4359ba5e9be18bc.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
28512be795 sys-libs/binutils-libs: Sync with Gentoo
It's from Gentoo commit 7eb007853b56957cc436df74c97a9e783411c125.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
5e8bc6216f sys-kernel/linux-headers: Sync with Gentoo
It's from Gentoo commit e9e6312d5a12a16bec692e44de3f184c0cc2dc5e.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00
Flatcar Buildbot
370cdeb36c sys-fs/mdadm: Sync with Gentoo
It's from Gentoo commit 88363d5349960e09082915da4e7e5b08e379c564.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-03-11 10:10:50 +01:00