34068 Commits

Author SHA1 Message Date
Flatcar Buildbot
9ed6473ae8 app-arch/unzip: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
61fb5443f1 app-arch/tar: Sync with Gentoo
It's from Gentoo commit 077e24df7d281752f422c32bb549963aadbf2072.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
657317c086 app-arch/sharutils: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
2771a93136 app-arch/rpm2targz: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
9ecf68203b app-arch/pigz: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
6be08c762a app-arch/pbzip2: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
c3e31b0e7d app-arch/ncompress: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
870728a820 app-arch/lzop: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
fe52e3025f app-arch/lz4: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
ea4b0d4d5d app-arch/libarchive: Sync with Gentoo
It's from Gentoo commit 203a8c1075d6b0bbeff5f099f75dcc1e491a810f.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
436262668e app-arch/lbzip2: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
64c23a17f2 app-arch/gzip: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
4797c5d07a app-arch/cpio: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
17efbd9b76 app-alternatives/yacc: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
6eea2add25 app-alternatives/tar: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
d7da184b46 app-alternatives/sh: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
7f5ee8e654 app-alternatives/ninja: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
8bc1d57fc9 app-alternatives/lex: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
12706d75d8 app-alternatives/gzip: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
98439b8794 app-alternatives/cpio: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
73e026f430 app-alternatives/bzip2: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
46bda4d2a3 app-alternatives/bc: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:40 +01:00
Flatcar Buildbot
8717102278 app-alternatives/awk: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:39 +01:00
Flatcar Buildbot
f4e43536ea app-admin/perl-cleaner: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:39 +01:00
Flatcar Buildbot
357d3f2222 app-admin/eselect: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:39 +01:00
Flatcar Buildbot
7b050f2b49 acct-user/portage: Sync with Gentoo
It's from Gentoo commit a838526d4d0bac69ba4b403154f78384be0034ff.

Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 17:36:39 +01:00
Daniel Zatovic
ddd38ae5ab changelog: Mention OEM sysext signing changes
Update the changelog entry to include information about OEM sysexts
being signed and built during the image phase.

Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
Daniel Zatovic
10b808642b sysext: Move OEM sysext build to image phase
Move OEM sysext building from the vms phase to the image phase. This
ensures OEM sysexts are signed with the same ephemeral key as other
sysexts, which is generated during image build and discarded afterward.

- Add create_oem_sysexts() to build all OEM sysexts during image build
- Add oem_sysexts.sh with OEM sysext definitions
- Update install_oem_sysext() to use prebuilt sysexts
- Add OEM sysext download to vms.sh for CI builds

Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
Daniel Zatovic
b3dfe61eea changelog: Add entry for signed OS-dependent sysexts
Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
Daniel Zatovic
3ffbf90154 sysext: Add OS-dependent sysext compression
We removed the sysext compression, because we double-compression is
redundant for sysexts stored in already coimpressed BTRFS /usr. However,
OS-dependent sysexts that are downloaded on-demand were now also
uncompressed. This commit brings back the compression via
SYSTEMD_REPART_MKFS_OPTIONS_EROFS option.

Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
Daniel Zatovic
0edeb6cb5c sysext: Sign OS-dependent sysexts
Generate an ephemeral sysext signing key, that is injected into the
image's sysext root of trust. All OS-dependent sysexts will be signed by
this key and the private key (stored in /tmp) will be discarded on SDK
container exit.

Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
Daniel Zatovic
9ef06f8928 overlay profiles: Enable cryptsetup in SDK systemd
The cryptsetup useflag is required for signing sysexts built with
systemd-repart.

Signed-off-by: Daniel Zatovic <daniel.zatovic@gmail.com>
2026-01-28 13:15:33 +01:00
James Le Cuirot
0a6a706520
Merge pull request #3673 from flatcar/vmware-13.0.10-main
Upgrade open-vm-tools in main from 13.0.5 to 13.0.10
2026-01-28 10:24:23 +00:00
Dongsu Park
d87f4c0a9b
Merge pull request #3648 from flatcar/firmware-20260110-main
Upgrade Linux Firmware in main from 20251125 to 20260110
2026-01-28 10:50:11 +01:00
flatcar-ci
f174e1b5b7 Revert failed version back to 4592.0.0+nightly-20260126-2100 2026-01-28 08:07:20 +00:00
Flatcar Buildbot
9185aa1d76 app-emulation/open-vm-tools: Update from 13.0.5 to 13.0.10
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-28 07:07:00 +00:00
flatcar-ci
b88fb61825 New version: main-4593.0.0-nightly-20260127-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-01-27 21:00:22 +00:00
Mathieu Tortuyaux
b0cbbcf492
Merge pull request #3669 from flatcar/mantle-update-main
Upgrade mantle container image to latest HEAD in main
2026-01-27 10:20:10 +01:00
Flatcar Buildbot
559513963d Update mantle container image to latest HEAD
Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
2026-01-27 08:58:19 +00:00
Dongsu Park
6041239da4
Merge pull request #3613 from flatcar/buildbot/monthly-glsa-metadata-updates-2026-01-01
Monthly GLSA metadata 2026-01-01
2026-01-27 09:58:04 +01:00
flatcar-ci
66995caefa New version: main-4592.0.0-nightly-20260126-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
main-4592.0.0-nightly-20260126-2100
2026-01-26 21:00:24 +00:00
Flatcar Buildbot
f222a71d8c portage-stable/metadata: Monthly GLSA metadata updates
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Dongsu Park <dongsu@dpark.io>
2026-01-26 13:27:54 +01:00
flatcar-ci
ade059da60 New version: main-4589.0.0-nightly-20260123-2100
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-01-24 03:00:01 +00:00
flatcar-ci
90f86ae905 New version: main-4589.0.0-nightly-20260123-2100-INTERMEDIATE
Signed-off-by: flatcar-ci <infra+ci@flatcar-linux.org>
2026-01-23 21:00:28 +00:00
Mathieu Tortuyaux
0a3e23bc59
Merge pull request #3661 from flatcar/krnowak/gnupg
Update gnupg packages
2026-01-23 14:23:11 +01:00
Krzesimir Nowak
d22c749c94 changelog: Add entries
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-01-23 14:16:03 +01:00
Krzesimir Nowak
1eed1066ab app-crypt/pinentry: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-01-23 13:57:16 +01:00
Krzesimir Nowak
0b21977c86 app-crypt/gpgme: Sync with Gentoo
It's from Gentoo commit 2d25fad95cbaa525c8945d8e582c749d49524f49.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-01-23 13:53:51 +01:00
Krzesimir Nowak
c0e9c0bbd1 app-alternatives/gpg: Sync with Gentoo
It's from Gentoo commit c5b26c6b223e02892a79b1836531fded7123b854.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-01-23 13:30:14 +01:00
Krzesimir Nowak
6f633aca2f dev-libs/npth: Sync with Gentoo
It's from Gentoo commit 9fbdb080f182155a33ff5f977d9c7fa2b2889db5.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
2026-01-23 13:14:07 +01:00