-
Notifications
You must be signed in to change notification settings - Fork 50
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Weekly portage-stable package updates 2023-10-09 #1223
Weekly portage-stable package updates 2023-10-09 #1223
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As a side note, in the selinux-container downstream patch, we can drop the following lines:
Lines 69 to 74 in 4a9ae3d
+# required for cilium, can be upstreamed | |
+# Jun 20 08:01:43 localhost audit[3480]: AVC avc: denied { open } for pid=3480 comm="cilium-agent" scontext=system_u:system_r:spc_t:s0 tcontext=system_u:system_r:spc_t:s0 tclass=perf_event permissive=1 | |
+# Jun 20 08:01:43 localhost audit[3480]: AVC avc: denied { kernel } for pid=3480 comm="cilium-agent" scontext=system_u:system_r:spc_t:s0 tcontext=system_u:system_r:spc_t:s0 tclass=perf_event permissive=1 | |
+# Jun 20 08:01:43 localhost audit[3480]: AVC avc: denied { cpu } for pid=3480 comm="cilium-agent" scontext=system_u:system_r:spc_t:s0 tcontext=system_u:system_r:spc_t:s0 tclass=perf_event permissive=1 | |
+# Jun 20 08:01:43 localhost audit[3480]: AVC avc: denied { read } for pid=3480 comm="cilium-agent" scontext=system_u:system_r:spc_t:s0 tcontext=system_u:system_r:spc_t:s0 tclass=perf_event permissive=1 | |
+allow spc_t self:perf_event { open cpu kernel read }; |
I upstreamed those: SELinuxProject/refpolicy@feaf607.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Cool, thanks for letting me know.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Er, I mean, this needs to wait until we pick up the update of sec-policy/selinux-container from Gentoo, right?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think it's already there: we're upgrading to selinux-container-2.20231002
and the commit is part of the release: RELEASE_2_20231002
(SELinuxProject/refpolicy@feaf607)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The ebuild is still unstable, so we didn't pick it up. Should we add accept keywords for it?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah yes indeed - then I guess we can follow Gentoo for this as we just upgraded the SELinux policies, no need to rush.
It's from Gentoo commit 33b88a8e44606ea675432dfb7b1cebb2037959d4.
It's from Gentoo commit c3eab6fa1db6e84500528a139a951c3a59874df8.
It's from Gentoo commit efb8fd83db0cdd062b100b763fa9e02609179081.
It's from Gentoo commit 8b1e46f54820a06a69e0573015ee33f67e04c1c3.
It's from Gentoo commit b5eb3cf25f865a8d75f149e5225db9febc832a7d.
It's from Gentoo commit 978d0361e4ce0e8e5c3b0a0c12a36611f03d0d2f.
It's from Gentoo commit abe5a47cda2a63c48c8dbf71a0fb642db6bb3032.
It's from Gentoo commit d5288953bcc343f811fd59179097dad1db206320.
It's from Gentoo commit 3f6342b1db6e23197fd2c7bbae588c8a9b0d3737.
It's from Gentoo commit b28fd4b74718fb4047db1baad10f0002d840f637.
It's from Gentoo commit d7204da98ae172d46089b350e1f7465eb617b743.
It's from Gentoo commit 4985f0705b618da6cf7ca5bf9c47af3cf94dab49.
It's from Gentoo commit a2fa1d1a29320ec6602d6cde2af8decbfe52069f.
It's from Gentoo commit 14d76e24d2cdcdfa69c280e68d96a0244c1ccc20.
It's from Gentoo commit c0ad7b00c772c71a74ec42be0bf594ee9198b71c.
It's from Gentoo commit cc7061ee5e3bfd1a7a1bcbdc44f1bd1d69fda495.
It's from Gentoo commit 1c74c5617c8c8094188eb2c99e3aae4867b5e22f.
It's from Gentoo commit 79853c374d5f3e0cf1a73a17fec44912739b7012.
It's from Gentoo commit d873e6b6f87b8a71f0376a04f1487b394add718b.
It's from Gentoo commit 948d91c1679ef28057c2ccc28e00a7bb6c027b77.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 699016c9b86c4154bb66e0657d3f3c264208141d.
It's from Gentoo commit 6cded3b440a889fbea35205c5c42ab70373b4ff6.
It's from Gentoo commit 68508019cec4a5622ffab2825ea9e8f6cdd42a84.
It's from Gentoo commit f5f361e355257f8098df5f56f7c43aed4b452831.
It's from Gentoo commit 444f42f73266981576e51d509ae26564ac1641cc.
It's from Gentoo commit 11e20405a1a8ffa9d7efe197ded0759846fa4256.
It's from Gentoo commit 0605ed4d84c009e2bf6236bf4d0181c35080f013.
It's from Gentoo commit 2692dfa901b96fca8a47b78967f6cf5a3d483dab.
08fe462
to
b5c45ad
Compare
CI passed. |
Build action triggered: https://github.com/flatcar/scripts/actions/runs/6494336660 |
CI: http://jenkins.infra.kinvolk.io:8080/job/container/job/sdk/1103/cldsv
--
app-arch/pigz: [PROD] [DEV]
app-portage/portage-utils: [DEV]
dev-libs/libxml2: [DEV]
dev-python/lxml: [DEV]
eclass/flag-o-matic.eclass:
net-dns/c-ares: [DEV]
net-misc/whois: [PROD] [DEV]
profiles:
sys-apps/portage: [DEV]
sys-devel/gcc: [DEV]
sys-devel/gdb: [DEV]
--