-
Notifications
You must be signed in to change notification settings - Fork 54
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Weekly portage-stable package updates 2023-11-27 #1423
Merged
dongsupark
merged 102 commits into
main
from
buildbot/weekly-portage-stable-package-updates-2023-11-27
Dec 18, 2023
Merged
Weekly portage-stable package updates 2023-11-27 #1423
dongsupark
merged 102 commits into
main
from
buildbot/weekly-portage-stable-package-updates-2023-11-27
Dec 18, 2023
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
It's from Gentoo commit 49e5a6834a2171fae91de0a5a6e54bff492dd7fe.
It's from Gentoo commit 51dc665cf37c6931981c81b7fdf7570ca592098a.
It's from Gentoo commit 76b75a5dfde7470a530ddfca3bf55fd00227f951.
It's from Gentoo commit dfa9e44f1f3e236230ebf9dc64ec3b31bd2ea070.
It's from Gentoo commit 347b890d7d5990eb94edc5328945abab684443ba.
It's from Gentoo commit 1738f215d210c3076e73ae2ee2e1c8dfc9914103.
It's from Gentoo commit 67e3098dacad21fd4cf7263a9caa945514c2267c.
It's from Gentoo commit d2337bc589e6659eb8589bb3885638a8d45da737.
It's from Gentoo commit 9edfdc3c8998055e798eee56fa4ffd052c847b2e.
It's from Gentoo commit c8299b2f5a461ce01a5b07f24d0be379bf6ab669.
It's from Gentoo commit 8d98f55a7064939ef3f85c73c13f19de98d73763.
It's from Gentoo commit e4a74ba7a3439a3ce96c881eb825ddad4b35dabc.
It's from Gentoo commit 0aa7e109c7a4d4df36e95359d928549abae45a7b.
It's from Gentoo commit 85073a762439ba152720026f71edfda72a486028.
It's from Gentoo commit fa1d095409ac018dbb423ca883d296813970804c.
It's from Gentoo commit cc5926b529b27a0a376f745452cfa8d7f6c841df.
It's from Gentoo commit 73cc4f969276789e4d8316656cc3805d1721ed9b.
It's from Gentoo commit 3331727427deec8acf5ce5826ede0e835259fc3e.
It's from Gentoo commit aaa875c761a02f7fd84b0ff9bab035f1e4e4c18b.
It's from Gentoo commit 911cd3f9a42d19db2f044bb5195810f19a41921a.
It's from Gentoo commit 4737eab9fd99a0969f7c2e0e701a6501e31bb916.
It's from Gentoo commit ba4aa6c93a7f59ae453fea0dd3377b6de512a0d1.
It's from Gentoo commit ea17c1e92e82313ced2b7bc8b7eca46a510c6268.
It's from Gentoo commit f562b54afc4c0f60e73cc50ac046cc43f9b9dbc5.
It's from Gentoo commit c40a71a8d1cc75f5b256006f87366e90b897bf83.
It's from Gentoo commit 09a48d7649ff8ec54062a0aa41d675aa3c0e88f9.
It's from Gentoo commit 0e053702e140119192a2d5f1cb2c2d1995d7eed1.
It's from Gentoo commit ff562a6365ad9f0ec33310812871bd753aeff2c0.
It's from Gentoo commit a3faba9c126ecea09476926b727365f1d0df8962.
It's from Gentoo commit 2f50bca02b84869cd6ac5c2ba6fb5caa05fcb362.
It's from Gentoo commit 649feb2f9d40830700fb6b2929c1266419d37e09.
It's from Gentoo commit 4728e4c99ba2a88c1f068150f5bbe6607466f1fb.
It's from Gentoo commit 522c58011e0a72e35160dc52d96e7d9e3f129ff7.
It's from Gentoo commit 7fe3a4d4ad1dcf3a5c440a84ff6d434dac7aaef5.
It's from Gentoo commit 1360a703f078299a9857a9baa706c6152b0a3c80.
It's from Gentoo commit 668d113bf9ad3fe39bc15964900730dc869832f4.
It's from Gentoo commit ba67223776736a2b8581677250d216b142500ac3.
It's from Gentoo commit 017bff0a540eab67bd9657d4455f13a62dbcca28.
…ntainer We need to enable net_raw capability for ping inside the docker container.
All the sec-policy/selinux-* packages contain policies from the same tarball. Which means that for the sake of consistency we should be applying our patches for every sec-policy/selinux- package. Currently we have six such packages, so for each of those packages have a symlink that points to the common selinux patches directory.
- Merge all the patches into one. Previously there were a bunch of smaller patches, but their filenames and their contents did not really explain what they were fixing. - Document some of the changes that we have made. Try to put as much information about our own modifications. - Drop deprecated killall(kernel_t), mcs_file_read_all(kernel_t), mcs_file_write_all(kernel_t), mcs_ptrace_all(kernel_t). - Add more changes to cover more of the AVCs we were getting.
krnowak
force-pushed
the
buildbot/weekly-portage-stable-package-updates-2023-11-27
branch
from
December 13, 2023 12:24
61a4425
to
18b7a0d
Compare
CI passed. Pinging @tormath1 for my SELinux changes. |
Build action triggered: https://github.com/flatcar/scripts/actions/runs/7195340218 |
dongsupark
approved these changes
Dec 14, 2023
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, but I have no idea about the SELinux part.
tormath1
approved these changes
Dec 18, 2023
dongsupark
deleted the
buildbot/weekly-portage-stable-package-updates-2023-11-27
branch
December 18, 2023 13:48
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
CI:
Closes flatcar/Flatcar#1254
SELinux changes:
--
app-alternatives/gzip: [PROD] [DEV]
app-arch/xz-utils: [PROD] [DEV]
app-crypt/pinentry: [DEV]
app-text/asciidoc: [DEV]
dev-lang/lua: [DEV]
dev-libs/elfutils: [DEV]
dev-libs/libgcrypt: [DEV]
dev-libs/libuv: [DEV]
dev-libs/nettle: [DEV]
dev-python/certifi:
dev-python/cython:
dev-python/lxml:
dev-util/bpftool: [PROD] [DEV]
dev-util/gperf: [DEV]
dev-util/meson:
dev-util/patchelf: [DEV]
eclass/acct-user.eclass:
eclass/distutils-r1.eclass:
eclass/flag-o-matic.eclass:
eclass/git-r3.eclass:
eclass/java-utils-2.eclass:
eclass/linux-mod-r1.eclass:
eclass/multibuild.eclass:
eclass/python-utils-r1.eclass:
eclass/toolchain-autoconf.eclass:
eclass/toolchain-funcs.eclass:
eclass/toolchain.eclass:
licenses:
net-dns/c-ares: [PROD] [DEV]
net-firewall/ipset: [DEV]
net-libs/libmicrohttpd: [DEV]
net-misc/bridge-utils: [DEV]
net-misc/curl: [DEV]
net-misc/ntp: [DEV]
net-misc/whois: [PROD] [DEV]
profiles:
sec-policy/selinux-base: [PROD] [DEV]
sec-policy/selinux-base-policy: [PROD] [DEV]
sec-policy/selinux-container: [PROD] [DEV]
sec-policy/selinux-dbus: [PROD] [DEV]
sec-policy/selinux-sssd: [PROD] [DEV]
sec-policy/selinux-unconfined: [PROD] [DEV]
sys-apps/debianutils: [DEV]
sys-apps/man-db: [DEV]
sys-apps/smartmontools: [DEV]
sys-block/thin-provisioning-tools: [DEV]
sys-devel/binutils: [DEV]
sys-devel/m4: [DEV]
sys-firmware/intel-microcode: [PROD] [DEV]
sys-libs/binutils-libs: [PROD] [DEV]
sys-libs/libnvme: [PROD] [DEV]
sys-libs/zlib: [PROD] [DEV]
sys-process/procps: [DEV]
--