30065 Commits

Author SHA1 Message Date
David Michael
992fe6682f Merge pull request #590 from dm0-/glsa
Fix GLSAs
2017-10-23 17:03:16 -07:00
David Michael
a7536845a3 Merge pull request #767 from dm0-/glsa
build_library: Whitelist the Go 1.9 GLSA
2017-10-23 17:03:06 -07:00
David Michael
e0f6100de8 build_library: Whitelist the Go 1.9 GLSA
We handle Go differently than Gentoo, so our 1.8.4 package includes
the same security fixes.  When all packages are built with Go 1.9,
the older Go packages shouldn't be installed anymore, so this line
can be dropped.
2017-10-23 14:35:52 -07:00
Euan Kemp
dcbc6a8686 dev_image_util: hardcode correct portage binhost
We already hardcode similar urls a bit below (the sync-uri).

Not hardcoding the binhost results in an incorrect value during
embargoed build uploads.
2017-10-23 14:14:58 -07:00
Euan Kemp
4a51d6f462 Merge pull request #2830 from euank/1.12-fail-faster
app-emulation/docker: bump for fail-faster patch
2017-10-23 12:10:28 -07:00
Stephen Demos
562e0670bc coreos-base/update-ssh-keys: req newer coreos-init
coreos-init versions older than 0.0.1-r152 still have the
update-ssh-keys shell script which means the update-ssh-keys package
fails to install. to fix this, we make coreos-base/update-ssh-keys block
on versions of coreos-init that are too old.
2017-10-23 12:00:12 -07:00
David Michael
dbc85258a7 Merge pull request #2846 from dm0-/glsa
profiles: Sync libpcre on arm64 for GLSAs
2017-10-23 11:59:26 -07:00
David Michael
167d1d6b54 profiles: Sync libpcre on arm64 for GLSAs 2017-10-23 11:34:36 -07:00
David Michael
39a3e3b890 bump(dev-libs/libpcre): sync with upstream 2017-10-23 11:30:27 -07:00
David Michael
c466ed4f47 bump(metadata/glsa): sync with upstream 2017-10-23 11:29:42 -07:00
Euan Kemp
c4dde55909 Merge pull request #2826 from euank/socat
coreos-base/coreos: add socat to base image
2017-10-23 10:32:51 -07:00
Euan Kemp
1f41089ac2 Merge pull request #588 from euank/socat
bump(net-misc/socat): sync with upstream
2017-10-23 10:31:16 -07:00
Euan Kemp
22ce951b35 coreos-base/coreos: add socat to base image
This is being added in no small part to better support running the
kubelet in more ways.

It adds up to a few hundred kbs of disk usage, and the benefit is some
tooling which desires to install the kubelet as a static binary on the
host can do so with fewer problems.
2017-10-23 10:22:28 -07:00
Euan Kemp
26a5960489 profiles: accept socat for arm64
We could have picked either readline or ssl as a thing to remove in
package.use since the license issue is ssl XOR readline.

I arbitrarily picked ssl. The primary consumer of socat, the kubelet,
needs neither.
2017-10-23 09:06:46 -07:00
David Michael
9854d19a5e dev-db/etcdctl: Bump to 3.2.9 2017-10-22 16:03:52 -07:00
David Michael
313f8f1b35 app-admin/etcd-wrapper: Bump to 3.2.9 2017-10-22 15:48:49 -07:00
David Michael
c1cec0a9cd Merge pull request #2844 from coreosbot/master-4.13.9
Upgrade Linux in master to 4.13.9
2017-10-22 14:02:18 -07:00
Jenkins OS
efcfa20d5d sys-kernel/coreos-sources: bump to 4.13.9 2017-10-22 17:15:12 +00:00
David Michael
06a3148747 Merge pull request #2836 from dm0-/gmerge
Check out release commits by default in dev images
2017-10-21 17:43:45 -07:00
Euan Kemp
8e54a220db Merge pull request #2839 from weikinhuang/kubelet-wrapper-hosts
app-admin/kubelet-wrapper: Specify hosts-entry to mount hosts file
2017-10-20 16:48:26 -07:00
Wei Kin Huang
3b5a57c009 app-admin/kubelet-wrapper: Specify hosts-entry to mount hosts file from host 2017-10-20 19:07:28 -04:00
Andrew Jeddeloh
767072aa09 Merge pull request #765 from ajeddeloh/rm-serve
serve.go: remove serve.go
2017-10-20 14:38:45 -07:00
Andrew Jeddeloh
1c83274945 serve.go: remove serve.go
No one noticed this was here. It is not used. python -m SimpleHTTPServer
does the same thing.
2017-10-20 14:19:36 -07:00
David Michael
e393ea75c5 coreos-base/cros-devutils: Bump to sync with gmerge
The changes in the commits shouldn't make a difference here, but it
is built from the same source as the gmerge package, so this makes
it look in sync.
2017-10-20 09:06:15 -07:00
David Michael
45aa51c900 coreos-base/gmerge: Bump to check out release commits 2017-10-20 09:06:15 -07:00
Benjamin Gilbert
35300beffa Merge pull request #2835 from coreosbot/master-4.13.8
Upgrade Linux in master to 4.13.8
2017-10-20 01:19:05 -07:00
Jenkins OS
24ed768112 sys-kernel/coreos-sources: bump to 4.13.8 2017-10-20 04:48:19 +00:00
David Michael
97040e32bf Merge pull request #2820 from sdemos/rust
coreos-base/{update-ssh-keys, coreos-metadata}: add rust packages
2017-10-19 19:49:15 -07:00
Benjamin Gilbert
e210eaa853 Merge pull request #764 from coreos/binutils
Revert binutils to 2.25 again
2017-10-19 19:29:16 -07:00
Benjamin Gilbert
af75a03a53 Merge pull request #2831 from coreos/binutils
profiles: Block binutils upgrades
2017-10-19 19:26:05 -07:00
Stephen Demos
018a504ee5 coreos-base/coreos: add update-ssh-keys as dep
we want to include the new standalone update-ssh-keys package in the os
build, so we add it as a dependency to the coreos-base/coreos
metapackage
2017-10-19 15:28:45 -07:00
Stephen Demos
a4b5c928f5 coreos-base/coreos-init: bump version
The newer version of coreos-init removes the update-ssh-keys script in
preparation for the standalone update-ssh-keys package. Without this
bump, the update-ssh-keys package will step on coreos-init's toes.
2017-10-19 15:28:45 -07:00
Stephen Demos
97987ef7f4 coreos-base/coreos-metadata: convert to rust
coreos-metadata has been rewritten in rust
(github.com/coreos/coreos-metadata#62). This modifies the ebuild to
use the coreos-cargo eclass to build the rust project.
2017-10-19 15:28:45 -07:00
Euan Kemp
6498dfc28f Merge pull request #2828 from coresolve/master
Address etcd-member race.
2017-10-19 15:07:24 -07:00
Duffie Cooley
0dfd2ec65e app-admin/etcd-wrapper: Address etcd-member race.
In some cases etcd is able to start before systemd-resolved has
populated the /etc/resolv.conf file. This commit addresses this by
adding a dependency on netowrk-online.target.

This will ensure that systemd-resolved finishes it's work before
etcd-member.service starts.
2017-10-19 14:40:35 -07:00
Stephen Demos
0bb6e97aee coreos-base/update-ssh-keys: add update-ssh-keys
this adds the update-ssh-keys package, which is a utility for managing
groups of openssh authorized public keys. the previous incarnation of
this utility included in the operating system was a shell script
included in init. it is now a rust binary living at
github.com/coreos/update-ssh-keys.

The update-ssh-keys shell script is removed from init in
ed478168f0133cc140baa08d4d77e4333e8991d7, github.com/coreos/init#256.
2017-10-19 13:05:47 -07:00
David Michael
b9e861c51d profiles: Block binutils upgrades 2017-10-19 08:45:38 -07:00
David Michael
20975049b3 Revert "update_chroot: Avoid a portage crash while upgrading binutils"
The binutils update prevents Linux from uncompressing during boot,
so this is being put off until it's fixed.

This reverts commit 5e659964d0d59471880609674eb1495449d8cbec.
2017-10-19 08:43:41 -07:00
David Michael
059a21701b build_library: Whitelist the binutils GLSA 2017-10-19 08:42:57 -07:00
Euan Kemp
a088127331 app-emulation/docker: bump for fail-faster patch 2017-10-18 18:02:41 -07:00
David Michael
45e0f36fc1 Merge pull request #2829 from dm0-/glsa
Fix GLSAs
2017-10-18 14:38:14 -07:00
David Michael
ff46bf1b9f Merge pull request #589 from dm0-/glsa
Fix GLSAs
2017-10-18 14:37:52 -07:00
David Michael
5b6fb6c908 net-dns/dnsmasq: Move back to portage-stable
It was moved here because of a broken Makefile.  The Makefile is
still weird, but not broken, so it can be moved back.
2017-10-18 14:37:14 -07:00
David Michael
bc6a0eabb6 profiles: Sync arm64 packages for security updates 2017-10-18 14:30:26 -07:00
David Michael
dd586b7355 bump(net-dns/dnsmasq): sync with upstream 2017-10-18 14:13:18 -07:00
David Michael
c6f9571a99 Merge pull request #2827 from dm0-/grub
sys-boot/grub: Sync and bump
2017-10-18 12:33:24 -07:00
David Michael
aa9897dafb bump(app-arch/libarchive): sync with upstream 2017-10-18 12:31:01 -07:00
David Michael
12c98a960f bump(metadata/glsa): sync with upstream 2017-10-18 12:25:42 -07:00
David Michael
11cfdef901 sys-boot/grub: Sync and bump
This syncs the ebuild with Gentoo, while preserving cros_workon and
cross-compiler targets.  It also bumps the commit to include a fix
for a use-after-free issue.
2017-10-17 15:40:50 -07:00
David Michael
f7faf7a8a3 Merge pull request #752 from dm0-/glsa
update_chroot: Avoid a portage crash while upgrading binutils
2017-10-16 23:27:07 -07:00