30065 Commits

Author SHA1 Message Date
Michael Marineau
b2bf0021ea Merge pull request #594 from marineam/disable-verity
build_image: disable verity again
2016-10-10 14:23:46 -07:00
Michael Marineau
4ed9a1a2a5 build_image: disable verity again
The Xen loader in GRUB never received support for our hacky scheme of
adding the verity hash to the kernel cmdline. Disable till that's fixed.

Partially reverts 2016567 and 533b1b9.
2016-10-10 14:08:05 -07:00
Michael Marineau
495fd3f9a1 Merge pull request #2223 from marineam/tzdata
Update to current timezone data
2016-10-10 12:43:43 -07:00
Michael Marineau
d0af59a49f Merge pull request #2225 from marineam/cgpt
sys-apps/seismograph: fix cgpt repair segfault
2016-10-10 12:40:14 -07:00
Michael Marineau
257121f734 Merge pull request #591 from marineam/utf-8
build_image: generate C.UTF-8 locale
2016-10-10 12:39:18 -07:00
Michael Marineau
92bc09f9da Merge pull request #2213 from marineam/utf-8
profiles: include libc locale data
2016-10-10 12:39:07 -07:00
Michael Marineau
bd8dd714d8 Merge pull request #2222 from marineam/ca-certs
app-misc/ca-certificates: update to latest mozilla cert db
2016-10-10 12:38:36 -07:00
Michael Marineau
4fe46f52d6 sys-apps/seismograph: fix cgpt repair segfault 2016-10-10 12:37:43 -07:00
Nick Owens
1a11e37c44 bump(dev-libs/libgcrypt): sync with upstream 2016-10-10 08:21:19 -07:00
Nick Owens
17948062a0 bump(metadata/glsa): sync with upstream 2016-10-10 08:18:00 -07:00
Michael Marineau
7560aeb81c sys-libs/timezone-data: remove management of /etc timezone
We omit /etc/localtime to use UTC by default.

Re-add the old posix symlink in the unlikely case someone is referring
to timezones using that prefix.
2016-10-07 16:05:28 -07:00
Michael Marineau
56adefa9db sys-libs/timezone-data: import latest stable ebuild from upstream 2016-10-07 15:46:47 -07:00
Michael Marineau
1c2346b1d2 app-misc/ca-certificates: update to latest mozilla cert db 2016-10-07 15:30:50 -07:00
Michael Marineau
f8e7c73802 Merge pull request #2221 from marineam/usrfiles
sys-libs/nss-usrfiles: sync w/ glibc 2.23
2016-10-07 14:25:22 -07:00
Michael Marineau
1d29705132 sys-libs/nss-usrfiles: sync w/ glibc 2.23
Fixes a few issues that have been resolved in glibc since 2.18:

 * The NSS backends shared internal state between thegetXXent and
   getXXbyYY NSS calls for the same database, causing a
   denial-of-service condition in some applications. (CVE-2014-8121)

 * Don't ignore too long lines in nss_files (CVE-2015-5277)
2016-10-07 14:16:18 -07:00
Joe Bowers
cb3e94e14b Merge pull request #2218 from joeatwork/roll-back-docker
Merge pull request #2215 from crawford/docker
2016-10-06 11:30:57 -07:00
Alex Crawford
3239c17a80 Merge pull request #2219 from crawford/systemd
sys-apps/systemd: bump to include various fixes
2016-10-05 15:22:34 -07:00
Alex Crawford
853caa3da1 sys-apps/systemd: bump to include various fixes 2016-10-05 14:37:41 -07:00
Alex Crawford
0982013ff0 app-emulation/runc: revert to 0.1.0 2016-10-05 14:01:42 -07:00
Alex Crawford
fe554c3f26 app-emulation/containerd: revert to 0.2.2 2016-10-05 14:01:33 -07:00
Alex Crawford
b8dc3c5213 app-emulation/docker: revert to 1.11.2 2016-10-05 14:01:21 -07:00
Michael Marineau
80b6905e1a Merge pull request #590 from marineam/verity
build_image: always enable verity when /usr is read-only
2016-10-03 11:22:34 -07:00
Geoff Levand
d71ba2963c Merge pull request #2214 from glevand/for-merge-oem-ec2-compat
coreos-base/oem-ec2-compat: Add arm64 keyword
2016-10-03 09:55:30 -07:00
Geoff Levand
6ba9759e19 coreos-base/oem-ec2-compat: Add arm64 keyword
Signed-off-by: Geoff Levand <geoff@infradead.org>
2016-09-30 16:04:25 -07:00
Michael Marineau
15f135b003 profiles: include libc locale data
This data can be later removed by build_image once it has run localedef
to generate the C.UTF-8 locale. When cross-compiling the glibc ebuild
won't run localedef so it is up to build image to handle.
2016-09-30 15:36:29 -07:00
Michael Marineau
533b1b9b02 build_image: always enable verity when /usr is read-only
Consolidates two very similar flags into one and fix an issue where
verity could get enabled in the GRUB config when rootfs verification was
turned off (e.g. on arm64 which cannot use verity yet).
2016-09-30 15:35:10 -07:00
Michael Marineau
9ed9ff7b45 build_image: generate C.UTF-8 locale 2016-09-30 15:24:32 -07:00
Alex Crawford
a269f1d2ab Merge pull request #2210 from coreos/revert-2153-gnupg-for-arm
Revert "app-crypt/gnupg: move from portage-stable and fix arm64 cross build."
2016-09-30 13:21:49 -07:00
Alex Crawford
d358d69032 Revert "app-crypt/gnupg: move from portage-stable and fix arm64 cross build." 2016-09-30 16:17:23 -04:00
Michael Marineau
32e99a8985 Merge pull request #2208 from marineam/seismograph
sys-apps/seismograph: update to 2.2, now includes rootdev
2016-09-30 11:12:30 -07:00
Michael Marineau
6a5552d0f0 sys-apps/seismograph: update to 2.2, now includes rootdev 2016-09-29 15:47:43 -07:00
Michael Marineau
386341878f Merge pull request #589 from marineam/verity
build_image: enable verity by default
2016-09-29 14:27:00 -07:00
Michael Marineau
6834ff2ea9 Merge pull request #2207 from marineam/verity
update_engine and mantle update
2016-09-29 14:26:22 -07:00
Michael Marineau
8361c45e6a mantle: bump to 0.2.1 2016-09-29 14:22:13 -07:00
Michael Marineau
5b5e0c2332 update_engine: bump to 0.4.0, PCR data support and bug fixes 2016-09-29 14:19:54 -07:00
Alex Crawford
3a6b1b0137 sys-kernel/coreos-modules: enable more mellanox 2016-09-29 14:04:12 -07:00
Alex Crawford
8375b0474b Merge pull request #2206 from crawford/bootengine
sys-kernel/bootengine: include qemu detection
2016-09-29 12:18:38 -07:00
Alex Crawford
860a1001cc sys-kernel/bootengine: include qemu detection 2016-09-29 11:44:01 -07:00
Michael Marineau
2016567d6f build_image: enable verity by default 2016-09-28 17:06:30 -07:00
Alex Crawford
15fe758ce1 Merge pull request #2153 from garygrebus/gnupg-for-arm
app-crypt/gnupg: move from portage-stable and fix arm64 cross build.
2016-09-28 14:03:41 -04:00
Alex Crawford
b5f2b0711c Merge pull request #2204 from crawford/locksmith
app-admin/locksmith: bump to v0.4.1
2016-09-27 19:34:35 -04:00
Alex Crawford
1888629087 app-admin/locksmith: bump to v0.4.1 2016-09-27 16:28:42 -07:00
Michael Marineau
29e35fe28a Merge pull request #588 from marineam/nobz2
offline_signing: vmlinuz is not bz2 compressed
2016-09-26 13:50:24 -07:00
Michael Marineau
d6b951c416 offline_signing: vmlinuz is not bz2 compressed 2016-09-26 13:44:45 -07:00
Nick Owens
c8b1f0096f Merge pull request #2198 from mischief/flannel-hosts
app-admin/flannel: mount /etc/hosts ro into flannel container
2016-09-23 13:33:36 -07:00
Michael Marineau
8469879619 Merge pull request #2202 from marineam/grub
grub: fix updating gpt on odd disk configurations
2016-09-23 12:42:54 -07:00
Michael Marineau
a3ecc9e964 grub: fix updating gpt on odd disk configurations 2016-09-23 12:36:24 -07:00
Nick Owens
e259eb25cb Merge pull request #2201 from mischief/flannel-0.6.2
app-admin/flannel: bump to v0.6.2
2016-09-22 17:03:04 -07:00
David Michael
e057f88598 Merge pull request #2200 from dm0-/bugs-981
Move early network configuration from kernel to initramfs
2016-09-22 15:57:58 -07:00
Nick Owens
3c30427f70 app-admin/flannel: bump to v0.6.2 2016-09-22 15:50:35 -07:00