Dongsu Park
9f31ccc3da
coreos-base/coreos-init: allow ssh-rsa in sshd_config
...
Temporarily accept ssh-rsa algorithm in sshd_config for openssh >= 8.8,
until most ssh clients could deprecate ssh-rsa.
Pulls in https://github.com/flatcar-linux/init/pull/54 .
2021-12-09 14:10:06 +01:00
Sayan Chowdhury
169872fa32
net-misc/openssh: Apply Flatcar patches
...
- Drop the init.d files.
- Remove the socket unit's rate limiting.
Signed-off-by: Sayan Chowdhury <schowdhury@microsoft.com>
Signed-off-by: Dongsu Park <dpark@linux.microsoft.com>
2021-12-09 14:10:04 +01:00
Sayan Chowdhury
884b45b252
profiles: accept ~arm64, ~amd64 for openssh 8.8_p1
...
Signed-off-by: Sayan Chowdhury <schowdhury@microsoft.com>
2021-12-09 14:10:02 +01:00
Dongsu Park
4f55795c91
net-misc/openssh: Sync with Gentoo upstream; updates to 8.8_p1
...
gentoo ref: 91c1a70f4c
Signed-off-by: Sayan Chowdhury <schowdhury@microsoft.com>
Signed-off-by: Dongsu Park <dpark@linux.microsoft.com>
2021-12-09 14:09:55 +01:00
Flatcar Buildbot
896c2f4622
sys-kernel: Upgrade Kernel 5.15.5 to 5.15.7
2021-12-09 07:24:27 +00:00
Dongsu Park
193cd0d8fc
Merge pull request #1485 from flatcar-linux/dongsu/ignition-text-cve
...
changelog: add missing CVE for golang.org/x/text in ignition
2021-12-08 15:19:40 +01:00
Dongsu Park
56fd2bd9eb
changelog: add missing CVE for golang.org/x/text in ignition
...
We missed CVE-2021-38561 when updating golang.org/x/text to 0.3.7 in
ignition.
2021-12-08 09:55:01 +01:00
Kai Lüke
8ad19b061b
Merge pull request #1482 from flatcar-linux/kai/kured
...
coreos-base/update_engine: Create reboot flag file for kured
2021-12-07 17:47:20 +01:00
Kai Lueke
5223857b20
coreos-base/update_engine: Create reboot flag file for kured
...
This pulls in
https://github.com/flatcar-linux/update_engine/pull/15 to create the
Ubuntu-compatible /run/reboot-required flag file for kured.
2021-12-07 17:20:09 +01:00
Dongsu Park
a58b53ff03
Merge pull request #1483 from flatcar-linux/rust-1.57.0-main
...
Upgrade dev-lang/rust in main from 1.56.1 to 1.57.0
2021-12-07 17:08:58 +01:00
Dongsu Park
88329aea97
Merge pull request #1474 from flatcar-linux/dongsu/mantle-golang-crypto-text
...
coreos-devel/mantle: update to 0.17.0-r1 for golang.org/x/{crypto,text}
2021-12-07 10:50:02 +01:00
Dongsu Park
36df933e3c
changelog: add changelog for mantle 0.17.0
...
Add changelog for mantle 0.17.0.
Also add changelog for security updates of golang.org/x/{crypto,text}
in mantle, as well as github.com/gogo/protobuf 1.3.2.
2021-12-07 10:03:11 +01:00
Flatcar Buildbot
309b013dcb
dev-lang: Upgrade dev-lang/rust 1.56.1 to 1.57.0
2021-12-07 07:44:47 +00:00
Dongsu Park
fbaae760e2
Merge pull request #1481 from flatcar-linux/runc-1.0.3-main
...
Upgrade Runc in main from 1.0.2 to 1.0.3
2021-12-06 14:31:44 +01:00
Dongsu Park
41ee028996
Merge pull request #1480 from flatcar-linux/cacerts-3.73-main
...
Upgrade ca-certificates in main from 3.72 to 3.73
2021-12-06 14:27:32 +01:00
Jeremi Piotrowski
3fd4bef291
Merge pull request #1454 from flatcar-linux/jepio+sayan/hyperv-arm64
...
Enable running as ARM64 HyperV guest
2021-12-06 09:59:56 +01:00
Dongsu Park
97a4fd9e4d
Merge pull request #1469 from flatcar-linux/dongsu/qemu-6.1.0
...
app-emulation/qemu: update to 6.1.0
2021-12-06 09:22:09 +01:00
Dongsu Park
b20eae536a
Merge pull request #1473 from flatcar-linux/dongsu/torcx-golang-crypto-text
...
app-arch/torcx: update golang.org/x/{crypto,text}
2021-12-06 09:17:29 +01:00
Flatcar Buildbot
e2d9556c3f
app-emulation: Upgrade Runc 1.0.2 to 1.0.3
2021-12-06 08:16:02 +00:00
Flatcar Buildbot
bea6aeda22
app-misc: Upgrade ca-certificates 3.72 to 3.73
2021-12-06 07:24:43 +00:00
Dongsu Park
82370a5847
coreos-devel/mantle: fix Github org name
...
Now that the Github org name of mantle was changed from coreos to
flatcar-linux, via https://github.com/flatcar-linux/mantle/pull/241 ,
we need to change the Github org name in ebuilds as well.
2021-12-03 16:11:51 +01:00
Dongsu Park
5b3bd625f9
coreos-devel/mantle: update to 0.17.0-r1 for golang.org/x/{crypto,text}
...
Update coreos-devel/mantle to 0.17.0-r1, to include the security updates
of golang.org/x/{crypto,text}, mainly to address CVE-2021-38561,
CVE-2021-43565.
Pulls in https://github.com/flatcar-linux/mantle/pull/262 .
2021-12-03 16:10:46 +01:00
Dongsu Park
219c7681b4
changelog: add changelog for golang.org/x/{crypto,text} in torcx
2021-12-03 15:14:12 +01:00
Dongsu Park
709e550b48
app-arch/torcx: update golang.org/x/{text,crypto}
...
Update golang.org/x/{text,crypto} mainly to address CVE-2021-38561,
CVE-2021-43565.
Pulls in https://github.com/flatcar-linux/torcx/pull/11 .
2021-12-03 15:14:03 +01:00
Krzesimir Nowak
1cf18fec64
Merge pull request #1470 from flatcar-linux/krnowak/bot-changelog
...
.github: Try to get a lwn link for kernel release
2021-12-03 14:44:03 +01:00
Dongsu Park
4f7cf03ea7
Merge pull request #1471 from flatcar-linux/go-1.17.4-main
...
Upgrade Go in main from 1.17.3 to 1.17.4
2021-12-03 14:02:18 +01:00
Dongsu Park
062afe6182
changelog: add changelog for qemu 6.1.0
2021-12-03 10:25:16 +01:00
Dongsu Park
7d3f49acdc
profiles: remove ~arm64 keywords for edk2-ovmf, ipxe, seabios, sgabios
...
As new versions of edk2-ovmf, ipxe, seabios, sgabios are already stable,
we do not need to keep the accept keywords. Delete them.
2021-12-03 10:24:29 +01:00
Dongsu Park
105d61c8d1
profiles: accept keywords for qemu 6.1.0-r1
...
Accept keywords for app-emulation/qemu 6.1.0-r1 for both ~amd64 and
~arm64.
2021-12-03 10:23:55 +01:00
Sayan Chowdhury
e127dfd040
app-emulation/qemu: Apply Flatcar patches
...
Allow python 3.6 in PYTHON_COMPAT for now.
Based on b541e937049757d5dd044ca2692036fc1805bd52.
2021-12-03 10:21:59 +01:00
Dongsu Park
ce3f18f6fa
app-emulation/qemu: update to 6.1.0
...
Update app-emulation/qemu to 6.1.0, mainly to address security issues
like CVE-2021-3682 .
2021-12-03 10:21:22 +01:00
Jeremi Piotrowski
ace70601c4
sys-kernel/coreos-modules: enable Microsoft MANA driver for amd64
...
New networking driver present in 5.15 that might be useful some day.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-12-03 09:03:23 +00:00
Jeremi Piotrowski
e75a689623
sys-kernel/coreos-modules: move HYPERV config options to commonconfig
...
Kernel 5.15 contains enablement patches for linux as a hyper-v guest, so
move the configs to the common config so that they're enabled for both
arches.
PCI patches didn't make it.
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-12-03 09:03:23 +00:00
Jeremi Piotrowski
20be55473f
coreos-base/oem-azure: refactor grub.cfg to apply console override only on PC
...
We always want the 'flatcar.autologin' parameter, but the ttyS0 setting is x86
PC specific. Move the generic part to linux_append variable and hide the
generic part behind a check for grub_platform. For EFI platforms the default
grub.cfg has the correct arch specific console configuration.
The console specification for grub itself is needed in either case
Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
2021-12-03 09:02:51 +00:00
Krzesimir Nowak
ac0c89da45
.github: Fail curl in kernel job on server errors too
...
Co-authored-by: Kai Lüke <pothos@users.noreply.github.com>
2021-12-03 08:52:09 +01:00
Flatcar Buildbot
c0e574fce9
dev-lang: Upgrade Go 1.17.3 to 1.17.4
2021-12-03 07:46:45 +00:00
Krzesimir Nowak
09b9f6ee71
.github: Try to get a lwn link for kernel release
2021-12-02 20:20:42 +01:00
Kai Lüke
097f137edb
Merge pull request #1468 from flatcar-linux/kai/flatcar-update
...
coreos-base/coreos-init: bump init repo to add flatcar-update tool
2021-12-02 17:33:47 +01:00
Kai Lueke
2093afe3eb
coreos-base/coreos-init: bump init repo to add flatcar-update tool
...
This pulls in https://github.com/flatcar-linux/init/pull/53 to add the
"flatcar-update" tool to the image, easing manual updates, rollbacks,
channel/release jumping, and airgapped updates.
2021-12-02 14:13:42 +01:00
Krzesimir Nowak
4c77918a91
Merge pull request #1462 from flatcar-linux/krnowak/bot-changelog
...
Teach github actions to generate changelog entries
2021-12-02 13:45:04 +01:00
Krzesimir Nowak
4bcbcb73e1
.github: Be fork friendly when checking target branches
...
We want to check if target branch exists on the repo on which the
action is being run and will get the PR in the end, not on repo with
which the SDK came. It's useful for testing github actions on personal
forks.
2021-12-02 13:29:44 +01:00
Krzesimir Nowak
1a6c155157
.github: Automatically generate the changelog entries
2021-12-02 12:40:10 +01:00
Krzesimir Nowak
4e58c5a422
.github: Simplify vmware package updates
...
Create just one commit that updates both open-vm-tools and
coreos-base/oem-vmware.
2021-12-02 12:40:10 +01:00
Krzesimir Nowak
d4f30c7274
.github: Add other packages into a patch when updating docker
...
Changes to docker-cli, docker-runc or torcx docker weren't included.
2021-12-02 12:40:10 +01:00
Krzesimir Nowak
2c33dcef76
.github: Add function for generating changelogs
...
The function only generates the update kind of changelogs. If the
update addresses some CVE, it needs to be added manually.
The changelog generation happens only if the changelog directory
exists. Also make sure it's included in the patches.
2021-12-02 12:40:10 +01:00
Kai Lüke
b81564c749
Merge pull request #1456 from flatcar-linux/kai/torcx-no-docker-1.12
...
app-arch/torcx: Fix wrong reference to Docker 19.03
2021-12-02 11:45:39 +01:00
Dongsu Park
e059a3bbf2
Merge pull request #1455 from flatcar-linux/dongsu/vim-8.2.3582
...
profiles: adjust profiles for vim 8.2.3582
2021-12-02 11:09:13 +01:00
Kai Lueke
48294d468a
app-arch/torcx: Fix wrong reference to Docker 19.03
...
When selecting the docker-1.12-no profile, torcx failed because the
profile looked for 19.03 instead of 20.10.
Make the docker-1.12-no profile identical to the vendor profile so
that we don't have to update it.
2021-12-01 17:54:49 +01:00
Dongsu Park
7984020e5f
profiles: disable crypt for amd64 and arm64
2021-12-01 13:48:55 +01:00
Dongsu Park
53aed3bbad
profiles: delete keywords for vim
2021-12-01 13:48:55 +01:00