Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

overlay sys-kernel/coreos-firmware: update to 20230625_p20230724 for main #1040

Merged
merged 4 commits into from
Aug 3, 2023

Conversation

dongsupark
Copy link
Member

@dongsupark dongsupark commented Aug 1, 2023

Update sys-kernel/coreos-firmware to 20230625_p20230724, mainly to address CVE-2023-20593.

Based on Gentoo commit 6390ce05738e.

Reset to Gentoo, apply Flatcar changes in a separate commit.

Fix issue of dealing with snapshot directory to avoid build failure.

See also flatcar/Flatcar#1134.

Testing done

CI: http://jenkins.infra.kinvolk.io:8080/job/container/job/packages_all_arches/2255/cldsv/

  • Changelog entries added in the respective changelog/ directory (user-facing change, bug fix, security fix, update)
  • Inspected CI output for image differences: /boot and /usr size, packages, list files for any missing binaries, kernel modules, config files, kernel modules, etc.

@dongsupark dongsupark added the main label Aug 1, 2023
@dongsupark dongsupark temporarily deployed to development August 1, 2023 13:45 — with GitHub Actions Inactive
@pothos
Copy link
Member

pothos commented Aug 1, 2023

For the image content/size diff I started http://jenkins.infra.kinvolk.io:8080/job/container/job/packages_all_arches/2243/cldsv/

@github-actions
Copy link

github-actions bot commented Aug 1, 2023

Build action triggered: https://github.com/flatcar/scripts/actions/runs/5748400458

@dongsupark
Copy link
Member Author

I am already running Jenkins CI http://jenkins.infra.kinvolk.io:8080/job/container/job/packages_all_arches/2242/cldsv/, with CI tests for a few more cloud providers. That is to be sure if it has no regression, especially because of the invasive changes done in this PR.

Update coreos-firmware to 20230625_p20230724, syncing with
linux-firmware of Gentoo, mainly to address CVE-2023-20593.

Gentoo ref: 6390ce05738eac80fc06663a73ca6b22fdaee8d1
Apply Flatcar modifications on top of Gentoo ebuilds.

* Specify coreos-* directories for Kernel builds.
* Use hard-coded linux-firmware directory instead of ${PN} as well as
  ${S} to avoid naming conflicts.
* Depend on packages of Kernel source and modules.
* Create symlinks for CXGB and ICE DDP firmware files.
* Rewrite src_prepare and src_install.
* Remove acenic/tg?.bin from unknown_license to force to install.
Add a license linux-fw-redistributable to ACCEPT_LICENSE, to be able to
build coreos-firmware as needed by linux-firmware of Gentoo.
@dongsupark dongsupark force-pushed the dongsu/firmware-20230625_p20230724-main branch from e9db08f to 388896f Compare August 2, 2023 11:29
@dongsupark dongsupark temporarily deployed to development August 2, 2023 11:29 — with GitHub Actions Inactive
@pothos
Copy link
Member

pothos commented Aug 2, 2023

I see that it removes a lot of firmware files. Is this intentional?

/rootfs-1/usr/lib/firmware/acenic
 -/rootfs-1/usr/lib/firmware/acenic/tg1.bin
 -/rootfs-1/usr/lib/firmware/acenic/tg2.bin
 -/rootfs-1/usr/lib/firmware/bnx2
 -/rootfs-1/usr/lib/firmware/bnx2/bnx2-mips-06-6.2.3.fw
 -/rootfs-1/usr/lib/firmware/bnx2/bnx2-mips-09-6.2.1b.fw
 -/rootfs-1/usr/lib/firmware/bnx2/bnx2-rv2p-06-6.0.15.fw
 -/rootfs-1/usr/lib/firmware/bnx2/bnx2-rv2p-09-6.0.17.fw
 -/rootfs-1/usr/lib/firmware/bnx2/bnx2-rv2p-09ax-6.0.17.fw
 -/rootfs-1/usr/lib/firmware/bnx2x
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e1-7.13.15.0.fw
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e1-7.13.21.0.fw
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e1h-7.13.15.0.fw
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e1h-7.13.21.0.fw
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e2-7.13.15.0.fw
 -/rootfs-1/usr/lib/firmware/bnx2x/bnx2x-e2-7.13.21.0.fw
 -/rootfs-1/usr/lib/firmware/ct2fw-3.2.5.1.bin
 -/rootfs-1/usr/lib/firmware/ctfw-3.2.5.1.bin
 -/rootfs-1/usr/lib/firmware/cxgb3
 -/rootfs-1/usr/lib/firmware/cxgb3/ael2005_opt_edc.bin
 -/rootfs-1/usr/lib/firmware/cxgb3/ael2005_twx_edc.bin
 -/rootfs-1/usr/lib/firmware/cxgb3/ael2020_twx_edc.bin
 -/rootfs-1/usr/lib/firmware/cxgb3/t3b_psram-1.1.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb3/t3c_psram-1.1.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb3/t3fw-7.12.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb4
 -/rootfs-1/usr/lib/firmware/cxgb4/t4fw-1.27.3.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb4/t4fw.bin
 -/rootfs-1/usr/lib/firmware/cxgb4/t5fw-1.27.3.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb4/t5fw.bin
 -/rootfs-1/usr/lib/firmware/cxgb4/t6fw-1.27.3.0.bin
 -/rootfs-1/usr/lib/firmware/cxgb4/t6fw.bin
 -/rootfs-1/usr/lib/firmware/e100
 -/rootfs-1/usr/lib/firmware/e100/d101m_ucode.bin
 -/rootfs-1/usr/lib/firmware/e100/d101s_ucode.bin
 -/rootfs-1/usr/lib/firmware/e100/d102e_ucode.bin
 -/rootfs-1/usr/lib/firmware/intel
 -/rootfs-1/usr/lib/firmware/intel/ice
 -/rootfs-1/usr/lib/firmware/intel/ice/ddp
 -/rootfs-1/usr/lib/firmware/intel/ice/ddp/ice-1.3.30.0.pkg
 -/rootfs-1/usr/lib/firmware/intel/ice/ddp/ice.pkg
  /rootfs-1/usr/lib/firmware/isci
  /rootfs-1/usr/lib/firmware/isci/isci_firmware.bin
 -/rootfs-1/usr/lib/firmware/mellanox
 -/rootfs-1/usr/lib/firmware/mellanox/lc_ini_bundle_2010_1006.bin
 -/rootfs-1/usr/lib/firmware/mellanox/mlxsw_spectrum-13.2010.1006.mfa2
 -/rootfs-1/usr/lib/firmware/mellanox/mlxsw_spectrum2-29.2010.1006.mfa2
 -/rootfs-1/usr/lib/firmware/mellanox/mlxsw_spectrum3-30.2010.1006.mfa2
 -/rootfs-1/usr/lib/firmware/myri10ge_eth_z8e.dat
 -/rootfs-1/usr/lib/firmware/myri10ge_ethp_z8e.dat
 -/rootfs-1/usr/lib/firmware/myri10ge_rss_eth_z8e.dat
 -/rootfs-1/usr/lib/firmware/myri10ge_rss_ethp_z8e.dat
 -/rootfs-1/usr/lib/firmware/phanfw.bin
 -/rootfs-1/usr/lib/firmware/qed
 -/rootfs-1/usr/lib/firmware/qed/qed_init_values_zipped-8.59.1.0.bin
 -/rootfs-1/usr/lib/firmware/ql2100_fw.bin
 -/rootfs-1/usr/lib/firmware/ql2200_fw.bin
 -/rootfs-1/usr/lib/firmware/ql2300_fw.bin
 -/rootfs-1/usr/lib/firmware/ql2322_fw.bin
 -/rootfs-1/usr/lib/firmware/ql2400_fw.bin
 -/rootfs-1/usr/lib/firmware/ql2500_fw.bin
 -/rootfs-1/usr/lib/firmware/rtl_nic
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8105e-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8106e-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8106e-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8107e-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8125a-3.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8125b-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8153a-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8153a-3.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8153a-4.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8153b-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8153c-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8156a-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8156b-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168d-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168d-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168e-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168e-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168e-3.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168f-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168f-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168fp-3.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168g-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168g-3.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8168h-2.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8402-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8411-1.fw
 -/rootfs-1/usr/lib/firmware/rtl_nic/rtl8411-2.fw
 -/rootfs-1/usr/lib/firmware/tigon
 -/rootfs-1/usr/lib/firmware/tigon/tg3.bin
 -/rootfs-1/usr/lib/firmware/tigon/tg3_tso.bin
 -/rootfs-1/usr/lib/firmware/tigon/tg3_tso5.bin

@pothos
Copy link
Member

pothos commented Aug 2, 2023

The firmware is still part of the upstream tree: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/tree/?id=59fbffa9ec8e4b0b31d2d13e715cf6580ad0e99c
I think this needs to be fixed.

@dongsupark
Copy link
Member Author

What you see is CI result of the previous version, from yesterday.
I discovered that issue earlier today, and fixed the issue ~1 hour ago.
And I am running the CI again, http://jenkins.infra.kinvolk.io:8080/job/container/job/packages_all_arches/2255/cldsv/.

@dongsupark dongsupark marked this pull request as ready for review August 2, 2023 15:27
@dongsupark
Copy link
Member Author

CI passed, and it does not have the issue of missing firmware any more.

@dongsupark dongsupark requested a review from a team August 3, 2023 08:27
Copy link
Member

@pothos pothos left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@dongsupark dongsupark merged commit bf2686c into main Aug 3, 2023
6 of 7 checks passed
@dongsupark dongsupark deleted the dongsu/firmware-20230625_p20230724-main branch August 3, 2023 12:43
This pull request was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants