3572 Commits

Author SHA1 Message Date
Andrew Jeddeloh
baecad72bc sys-fs/e2fsprogs: Trim unneeded files 2016-05-26 17:36:21 -07:00
Andrew Jeddeloh
eafd56358c sys-fs/e2fsprogs: Move from portage_stable 2016-05-26 17:32:36 -07:00
Matthew Garrett
6dc592af52 sec-policy/selinux-virt: Allow setattr on devpts ptys and grant pipefs access
Policy was blocking the modification of attributes on devpts ptys, making it
impossible to enter a rkt container interactively. Fix that. In addition,
pipefs access is being blocked which makes Docker unhappy. Fix that too.
2016-05-23 16:17:42 -07:00
Alex Crawford
148dad4459 Revert "app-emulation/docker: remove new TasksMax limit"
This reverts commit 345ee26b28a12e8866fa64a5ef7fb80c55cf656b.
2016-05-23 14:15:29 -07:00
Michael Marineau
c2b2e46f41 update_engine: enable build for arm64 2016-05-20 12:24:19 -07:00
Michael Marineau
8db2df9a69 Merge pull request #1979 from marineam/update-protobuf
profiles: update protobuf from 1.5 to 1.6
2016-05-20 12:21:24 -07:00
Michael Marineau
09e7641967 mantle: update to 0.1.5 2016-05-19 10:49:04 -07:00
Nick Owens
c23c9824fe profiles: fix e2fsprogs category botch 2016-05-19 10:33:58 -07:00
Nick Owens
131ae640de profiles: accept newer e2fsprogs to sync with e2fsprogs-libs 2016-05-19 10:11:02 -07:00
Alex Crawford
81287a2716 profiles: accept ~arm64 for e2fsprogs 2016-05-19 09:53:33 -07:00
Alex Crawford
764c089690 Merge pull request #1977 from crawford/ignition
sys-apps/ignition: bump to v0.6.0
2016-05-18 17:19:54 -07:00
Alex Crawford
0519456d98 Merge pull request #1976 from crawford/cloudinit
coreos-base/coreos-cloudinit: bump to v1.11.0
2016-05-18 17:19:49 -07:00
Alex Crawford
40b69e1113 sys-apps/ignition: bump to v0.6.0 2016-05-18 17:16:44 -07:00
Alex Crawford
aab6171fe7 Merge pull request #1955 from crawford/ignition
coreos-base/oem-gce: remove legacy scripts
2016-05-18 17:15:55 -07:00
Alex Crawford
569f038f1f coreos-base/coreos-cloudinit: bump to v1.11.0 2016-05-18 17:11:35 -07:00
Michael Marineau
3660e2edce profiles: stop disabling SHA512 password hashes in PAM
Likely inherited from ChromeOS but even for them it is a completely
ridiculous flag to disable. We had SHA512 enabled pre-PAM since shadow
does not have this use flag so this restores previous behavior.
2016-05-18 16:07:07 -07:00
Alex Crawford
b966515b82 coreos-base/oem-gce: remove legacy scripts
Provisioning will be handled by Ignition and coreos-metadata instead.
2016-05-18 14:59:39 -07:00
Michael Marineau
82f983f394 coreos-init: update gpg key in coreos-install 2016-05-18 14:52:11 -07:00
Alex Crawford
1ee0a6097c Merge pull request #1953 from crawford/google-compute-daemon
app-emulation/google-compute-daemon: bump to 1.3.2
2016-05-18 14:37:08 -07:00
Nick Owens
6ca8d8f064 Merge pull request #1967 from mischief/linux-4.6
Linux 4.6
2016-05-18 13:40:37 -07:00
Matthew Garrett
38b0befb11 Merge pull request #1965 from mjg59/pam_fix
sys-auth/pambase: Fall back to pam_deny in auth
2016-05-18 13:37:04 -07:00
Michael Marineau
c3b32ec05a Merge pull request #1972 from marineam/drop-protobuf-c
hard-host-depends: remove protobuf-c, nothing uses it
2016-05-18 11:14:51 -07:00
Michael Marineau
06b424a5a2 Merge pull request #1971 from marineam/update_engine
update_engine: update live ebuild for current master
2016-05-18 11:14:11 -07:00
Michael Marineau
8fbd548a87 rkt: add rkt-admin group, has access to /etc/rkt 2016-05-18 06:38:10 -07:00
Michael Marineau
815193f7ba profiles: update protobuf from 1.5 to 1.6
The newer version is needed for arm64, and need the same version across
all architectures because the build host and target's version must match.
2016-05-17 23:31:17 -07:00
Michael Marineau
f53b3ffc81 update_engine: add slot dependency for protobuf
Ensures that update_engine will get rebuilt when protobuf is upgraded.
2016-05-17 23:21:41 -07:00
Michael Marineau
5db17fb04d hard-host-depends: remove protobuf-c, nothing uses it 2016-05-17 23:01:56 -07:00
Michael Marineau
4292c9852f update_engine: update live ebuild, adding glog and removing libchrome 2016-05-17 22:04:48 -07:00
Michael Marineau
1f96cbc36d update_engine: split live and current stable ebuilds
Live ebuild needs different dependencies.

Drop invalid arm64 stable keyword, the old revision of update_engine
doesn't build on arm64. It is in package.provided instead.
2016-05-17 22:04:43 -07:00
Matthew Garrett
39745a7076 coreos-base/coreos-dev: remove dhcp
New versions of dhcp are difficult to cross build and we don't need it
anyway
2016-05-17 16:41:58 -07:00
Nick Owens
5ed74b61d7 app-emulation/rkt: v1.6.0 2016-05-16 15:26:23 -07:00
Nick Owens
3a95c8f18d sys-kernel/coreos-firmware: update to 20160331 2016-05-16 14:55:02 -07:00
Nick Owens
276a7f6d67 sys-kernel/coreos-{sources,kernel}: update to 4.6 2016-05-16 14:55:01 -07:00
Alex Crawford
80d7aed53d app-emulation/google-startup-script: bump to 1.3.2 2016-05-16 14:50:17 -07:00
Alex Crawford
12509babed app-emulation/google-compute-daemon: bump to 1.3.2 2016-05-16 14:50:17 -07:00
Matthew Garrett
a25497dce5 coreos-devel/mantle: Verify that unauthenticated users can't access CoreOS
Include a test to ensure that users without valid authentication tokens are
unable to log into CoreOS
2016-05-16 13:36:03 -07:00
Matthew Garrett
3ba6985d62 sys-apps/baselayout: Remove login shell for operator user 2016-05-16 13:36:03 -07:00
Matthew Garrett
3865f77ecd sys-auth/pambase: Fall back to pam_deny in auth
Setting pam_unix and pam_sss to sufficient means that if both fail,
control will be passed to the following pam module. If this is
pam_permit then permission will be granted even if the previous modules
failed. Switch to pam_deny and require it rather than permitting it to
be optional - if sss or unix succeed, we'll jump out before we get to
this point.
2016-05-15 21:12:57 -07:00
Nick Owens
4a94f04736 Merge pull request #1961 from mischief/linux-4.5.4
sys-kernel/coreos-{sources,kernel}: update to 4.5.4
2016-05-14 13:32:33 -07:00
Nick Owens
948af5c88b sys-kernel/coreos-{sources,kernel}: update to 4.5.4 2016-05-13 15:46:54 -07:00
Nick Owens
6b014521c4 sys-apps/systemd: bump to include DefaultTasksMax fix 2016-05-13 15:21:13 -07:00
Nick Owens
ee3d88085f Merge pull request #1958 from mischief/fix-rkt-stage1
app-emulation/rkt: use CoreOS alpha 1010.1.0 without PAM
2016-05-13 10:41:58 -07:00
Nick Owens
acf641ca67 app-admin/kubelet-wrapper: fix stage1 reference
since rkt 1.3.0, rkt has began checking stage1 hashes, and will do so if
the stage1 is not in the default stage1 directory. for compatibility,
df131e85d5240a75fb9cd4e1fb85e86e6f5290c1 symlinked the old stage1
directory to the new one, however, if a stage1 is referred to by the old
stage1 path under rkt >1.3.0, image verification will fail because no
signature exists.

instead of using a path, use stage1-fly.aci by name and let rkt handle
finding it in the default directory.
2016-05-12 21:39:13 -07:00
Nick Owens
05856d1789 app-emulation/rkt: use CoreOS alpha 1010.1.0 without PAM
CoreOS 1029.0.0 introduced PAM which was linked into systemd. rkt copies
files and libraries out of CoreOS images with a static manifest to
construct the CoreOS stage1. since this manifest lacks PAM libraries in
rkt 1.5.1, we can't use CoreOS 1032.0.0, so fall back to a CoreOS
version without PAM linked into systemd.
2016-05-12 21:31:25 -07:00
Michael Marineau
787c7beaf0 chore(metadata): Regenerate cache 2016-05-11 15:50:57 -07:00
Michael Marineau
aa0b0b9843 mantle: small fix for plume release 2016-05-11 11:12:55 -07:00
Michael Marineau
b96c191cf8 Merge pull request #1951 from marineam/go-arch
eclass/coreos-go: add ppc64 and x86 arch to go_get_arch
2016-05-10 19:22:53 -07:00
Nick Owens
be06aefc19 Merge pull request #1952 from mischief/mantle-0.1.2
coreos-devel/mantle: bump to v0.1.2
2016-05-10 13:39:15 -07:00
Nick Owens
a606b3942f coreos-devel/mantle: bump to v0.1.2 2016-05-10 13:33:23 -07:00
Nick Owens
d36cdc0c67 Merge pull request #1949 from mischief/linux-4.5.3
sys-kernel/coreos-{sources,kernel}: update to 4.5.3
2016-05-10 12:32:58 -07:00