Krzesimir Nowak
edcdfb51ea
profiles: Drop net-libs/libnetfilter_conntrack from accept_keywords
...
The updated package is stable for both amd64 and arm64.
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
84673e50f0
profiles: Drop outdated use flag for net-dns/bind-tools
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
fb869eb7a3
profiles: Drop sys-fs/multipath-tools from accept_keywords
...
The updated package is stable for both amd64 and arm64.
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
86cb489943
profiles: Drop outdated use flag for net-analyzer/tcpdump
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
770e86a737
profiles: Update accept_keywords for net-firewall/conntrack-tools
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
8b22921049
profiles: Drop net-libs/libnetfilter_queue from accept_keywords
...
The updated package is stable for both amd64 and arm64.
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
23e9e04eeb
profiles: Drop dev-libs/elfutils from accept_keywords
...
The updated package is stable for both amd64 and arm64.
2022-03-30 20:03:18 +02:00
Krzesimir Nowak
54180d667b
Merge pull request #1724 from flatcar-linux/krnowak/drop-intltool
...
coreos-base/hard-host-depends: Stop pulling in intltool
2022-03-30 18:50:21 +02:00
Dongsu Park
74dd64cce9
Merge pull request #1775 from flatcar-linux/dongsu/gnutls-3.7.3
...
profiles: delete keywords for gnutls
2022-03-30 15:53:45 +02:00
Jeremi Piotrowski
163effa73b
Merge pull request #1777 from flatcar-linux/jepio/coreos-sources-hyperv-backport
...
coreos-sources: backport hyperv coherence fixes
2022-03-30 15:29:52 +02:00
Jeremi Piotrowski
f49c0cfe73
Merge pull request #1765 from flatcar-linux/linux-5.15.32-main
...
Upgrade Linux Kernel in main from 5.15.31 to 5.15.32
2022-03-30 15:29:20 +02:00
Jeremi Piotrowski
e498f55aaf
sys-kernel/coreos-sources: backport kernel patches that fix memory coherence on Hyper-V
...
This is v3 of the patchset from here:
https://lore.kernel.org/lkml/1648138492-2191-1-git-send-email-mikelley@microsoft.com/T/#u
There was a slight merge conflict because hv_map_memory/hv_unmap_memory don't
exist in 5.15.
2022-03-30 13:13:11 +02:00
Kai Lüke
52b2ecfbbc
Merge pull request #1770 from flatcar-linux/mantle-update-main
...
Upgrade mantle to latest HEAD in main
2022-03-30 12:53:09 +02:00
Dongsu Park
1aa0a5b4a7
profiles: delete keywords for gnutls
...
As we update gnutls to 3.7.3-r1 which is already stable, there is
no need to accept keywords for gnutls. Delete.
2022-03-30 10:20:37 +02:00
Flatcar Buildbot
9847794b4f
sys-kernel: Upgrade Kernel 5.15.31 to 5.15.32
2022-03-30 08:24:53 +02:00
Flatcar Buildbot
35ecf3f62c
Update mantle commit to latest HEAD
2022-03-30 05:42:24 +00:00
Jeremi Piotrowski
cb4c868253
Merge pull request #1768 from flatcar-linux/jepio/mantle-update-action
...
github/workflows: add mantle update action
2022-03-30 07:42:07 +02:00
Jeremi Piotrowski
f33072ddfb
github/workflows: add mantle update action
...
This action runs over main and the release branches and creates a PR that
updates mantle reference to the latest one. By using a fixed branch name,
rerunning the action will update/close an existing PR if new mantle commits
happen or if the PR becomes obsolete.
2022-03-29 15:59:12 +02:00
Mathieu Tortuyaux
0cbc562928
Merge pull request #1767 from flatcar-linux/tormath1/unconfined
...
sec-policy/selinux-unconfined: move to ::portage-stable
2022-03-29 15:55:39 +02:00
Krzesimir Nowak
3f07ae6f09
Merge pull request #1708 from flatcar-linux/krnowak/pkg-updates-2019
...
Profile cleanups for updated packages from 2019
2022-03-29 15:45:09 +02:00
Krzesimir Nowak
44c82bb8c5
coreos-base/hard-host-depends: Stop pulling in intltool
...
The tool is deprecated, nothing pulls that in any more and it has a
dependency on dev-perl/XML-Parser, an updated version of which would
want to pull a bunch of new packages through dev-perl/libwww-perl.
Avoid the hassle and drop the tool.
2022-03-29 13:21:53 +02:00
Krzesimir Nowak
11917036f8
coreos-base/hard-host-depends: Sort the deps
...
Otherwise no changes done here.
2022-03-29 13:15:59 +02:00
Krzesimir Nowak
2ed433c6cc
sys-auth/realmd: Add new patches, update deps
...
Realmd didn't have dev-util/intltool listed as a dependency, but it
actually required it during build. Apply a patch from upstream that
converts the project from intltool to gettext in order to get rid of
the dependency on the obsolete tool. To apply the patch without
conflicts, apply also another patch from upstream that modernizes the
configure.ac file.
We also disable the i18n through the --disable-nls flag. The disabling
is not complete though, so we still need to point gettext to the ITS
rules we have installed in ROOT.
2022-03-29 13:14:27 +02:00
Mathieu Tortuyaux
65107a9d0f
sec-policy/selinux-unconfined: move to ::portage-stable
...
There is no Flatcar patches for this package.
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2022-03-29 10:11:23 +02:00
Krzesimir Nowak
167c1e5ebf
Merge pull request #1756 from flatcar-linux/linux-5.15.31-main
...
Upgrade Linux Kernel in main from 5.15.30 to 5.15.31
2022-03-24 19:34:55 +01:00
Mathieu Tortuyaux
948f39a141
Merge pull request #1760 from flatcar-linux/tormath1/bootengine
...
sys-kernel/bootengine: add cryptsetup in initramfs
2022-03-24 17:00:58 +01:00
Mathieu Tortuyaux
743f7c470f
changelog: add entry
...
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
Co-authored-by: Kai Lüke <pothos@users.noreply.github.com>
2022-03-24 17:00:10 +01:00
Mathieu Tortuyaux
c608794004
sys-kernel/bootengine: add cryptsetup in initramfs
...
this is required to run luks encryption with ignition
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2022-03-24 17:00:10 +01:00
Flatcar Buildbot
60b5b921ad
sys-kernel: Upgrade Kernel 5.15.30 to 5.15.31
2022-03-24 15:14:13 +01:00
Dongsu Park
87ed710ec2
Merge pull request #1745 from flatcar-linux/sayan/update-util-linux-2.37.4
...
profiles: disable su USE flag for util-linux
2022-03-24 10:27:32 +01:00
Jeremi Piotrowski
f5b92b623f
Merge pull request #1757 from flatcar-linux/jepio/workflows-lbzip2
...
.github/workflows: install lbzip2 to speed up sdk creation
2022-03-24 10:10:54 +01:00
Jeremi Piotrowski
cdd948d1c6
.github/workflows: install lbzip2 to speed up sdk creation
...
Our github actions use cork to create an sdk chroot, which pulls down bzipped
archives. The runners have 2 CPUs, so this unpacking could be faster if we
installed lbzip2. Cork transparently uses lbzip2.
2022-03-24 09:46:25 +01:00
Kai Lüke
9fdc34e13c
Merge pull request #1750 from flatcar-linux/kai/go-binary-size
...
eclass/coreos-go.eclass: strip Go binaries by default
2022-03-23 21:39:26 +01:00
Krzesimir Nowak
6c648087b3
Merge pull request #1751 from flatcar-linux/krnowak/bump-mantle
...
coreos-devel/mantle: Bump to latest commit
2022-03-23 14:51:32 +01:00
Krzesimir Nowak
d4850a6c86
coreos-devel/mantle: Bump to latest commit
2022-03-23 14:01:09 +01:00
Krzesimir Nowak
4a64240099
fixup! eclass/coreos-cargo: Ensure the modified config is valid TOML
2022-03-23 13:48:52 +01:00
Kai Lueke
e73121db37
eclass/coreos-go.eclass: strip Go binaries by default
...
The size contains not only of the /usr partition but also the /boot
partition require that we reduce the size of binaries as much as
possible.
Strip all Go binaries by default.
2022-03-23 13:11:15 +01:00
Krzesimir Nowak
090680dc6d
Merge pull request #1746 from flatcar-linux/krnowak/emerge-gitclone-pr-fix
...
coreos-base/emerge-gitclone: Pull PRs properly
2022-03-22 19:47:43 +01:00
Mathieu Tortuyaux
e3d384eb6c
Merge pull request #1747 from flatcar-linux/tormath1/cryptsetup
...
profiles/base: enable `fips` across the OS
2022-03-22 16:26:05 +01:00
Krzesimir Nowak
97e608f538
coreos-base/emerge-gitclone: Pull PRs properly
...
This usually doesn't happen for releases, but for development
dev-containers it might be the case that portage-stable or
coreos-overlay commit is specified as some pull request reference -
these need to be fetched differently, as refs from refs/pull usually
are not fetched by default.
2022-03-22 16:21:07 +01:00
Mathieu Tortuyaux
21ef6d148d
changelog: add entry
...
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2022-03-22 13:54:19 +01:00
Mathieu Tortuyaux
4f200d79ea
profiles/coreos/base: enable fips across the OS
...
only support by OpenSSL and Cryptsetup for now.
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2022-03-22 13:43:14 +01:00
Krzesimir Nowak
7acca26ab6
coreos-base/afterburn: Add dependency on dev-libs/openssl
...
The package depends on it through the openssl crate. Without openssl,
the package would fail to build because of missing header files.
2022-03-22 10:26:03 +01:00
Krzesimir Nowak
14ec0b2456
eclass/coreos-cargo: Ensure the modified config is valid TOML
...
We were appending the [build] section, and the updated cargo eclass
already added that to the config, so we ended up with having two
[build] sections in the config file. Try to amend the section instead
of appending it to the file. While at it, do the same with the
target.${RUST_TARGET} section too to be a bit more futureproof.
2022-03-22 10:26:03 +01:00
Krzesimir Nowak
f302e69455
coreos-base/update-ssh-keys: Bump EAPI to 8
...
EAPI 6 is too old for cargo eclass that gets inherited through
coreos-cargo.
2022-03-22 10:26:03 +01:00
Krzesimir Nowak
ab735a5df4
coreos-base/afterburn: Bump EAPI to 8
...
EAPI 6 is too old for cargo eclass that gets inherited through
coreos-cargo.
2022-03-22 10:26:03 +01:00
Krzesimir Nowak
5eccaeb306
profiles: Update accept_keywords for dev-lang/nasm
...
It is available for arm64 now, but still as unstable.
2022-03-22 10:26:03 +01:00
Krzesimir Nowak
9dec83eaa9
profiles: Drop app-misc/jq from accept_keywords
...
The updated package is stable for both amd64 and arm64.
2022-03-22 10:26:03 +01:00
Mathieu Tortuyaux
00cbb4bb25
profiles/base: accept tested version of cryptsetup
...
it's required to pull fips support
Signed-off-by: Mathieu Tortuyaux <mtortuyaux@microsoft.com>
2022-03-22 09:55:19 +01:00
Krzesimir Nowak
32941dc278
Merge pull request #1712 from JAORMX/sssd-selinux-module
...
Add sssd to list of SELinux modules enabled
2022-03-21 18:20:08 +01:00