Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Weekly portage-stable package updates 2024-05-13 #1982

Conversation

github-actions[bot]
Copy link

@github-actions github-actions bot commented May 13, 2024

CI: http://jenkins.infra.kinvolk.io:8080/job/container/job/sdk/1485/cldsv/

Closes flatcar/Flatcar#1454
Closes flatcar/Flatcar#1456

Blocked on flatcar/bootengine#97

--

--

  • changelog
  • image diff

@krnowak
Copy link
Member

krnowak commented May 22, 2024

@flatcar/flatcar-security-team: tpm2 package updates fix CVE-2024-29038, CVE-2024-29039 and CVE-2024-29040. I haven't seen an issue filed about them, so should I assume that these are not affecting us?

Copy link
Author

github-actions bot commented May 22, 2024

Build action triggered: https://github.com/flatcar/scripts/actions/runs/9795341968

@krnowak krnowak force-pushed the buildbot/weekly-portage-stable-package-updates-2024-05-13 branch from 40fe518 to 7eb74c4 Compare May 22, 2024 12:47
@dongsupark
Copy link
Member

@krnowak: Thanks. Created an issue flatcar/Flatcar#1454

@@ -1 +1,3 @@
DIST podman-4.9.4.tar.gz 21733620 BLAKE2B 17d099c0a13fbbb77556742313c39995127fc97b4086ef3c2d74a92cc0a4f825a6c729dd099c6d4f4cd3d2ebfd470494babdeaa85a5653b327ea1a16fb5ea993 SHA512 7b52555789a1c214fcf26b0826bdda6cf0ccca588f87c0f15ac5e8358ddac625e17cafbe6a43de07cad964e1418b5ee0d2e38a5cb5dc6f6d4e638399749a7f7b
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fail to build in the CI. What I don't get is that in the CI the version 4.9.4 is being built. While we're shipping the version 5.0.2 (http://bincache.flatcar-linux.net/images/amd64/3975.0.0/flatcar-podman_packages.txt).
I think the initial import is not a direct import from Gentoo: c692687#diff-c67bda60496165e7503813906b2e4a513ad7a564a349348986c7358f234b62e4

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's possible, because net-misc/passt (which is a dependency of podman) also wasn't a pristine copy from Gentoo. I'll investigate.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep, not a pristine import, see commit 7c775f6.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the contributor was not aware of this and we missed it at the review. Same thing for sysext Python (which is not yet merged): #1979 (comment)

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To sort this, I would suggest to do the pristine import and mark podman-5.0.2 as stable (to avoid having a downgrade of the sysext image).

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, that's what I'm doing at the moment. We got a bunch of packages imported in the podman PR, so I'm cleaning this up.

@tormath1 tormath1 mentioned this pull request May 27, 2024
2 tasks
@krnowak krnowak force-pushed the buildbot/weekly-portage-stable-package-updates-2024-05-13 branch from 7eb74c4 to cd69b92 Compare May 28, 2024 15:27
Flatcar Buildbot and others added 15 commits May 30, 2024 16:24
It's from Gentoo commit 00aadd9b5059a0675edb18cbb3278059b987ed24.
It's from Gentoo commit fb01593108774e0a1d207eb55388a7c04b225ac6.
It's from Gentoo commit 794061a3298b5716db015defa7b3e2c583b73980.
It's from Gentoo commit 794061a3298b5716db015defa7b3e2c583b73980.
It's from Gentoo commit 794061a3298b5716db015defa7b3e2c583b73980.
It's from Gentoo commit 70fc2a87a8c088bd47007c7e2c3954ed831e156d.
It's from Gentoo commit e2dccca015a4d53bf20e3db1577e0c8bf805813b.
It's from Gentoo commit b1bd5d199e46738f80666d4171726fc0941566b7.
It's from Gentoo commit b334e317a509df22a00706212645ab85cbabe2c5.
It's from Gentoo commit 1728e374db8721b71bad2ad4ac1e76e949849a5f.
It's from Gentoo commit 1d6ef8b3872ab702dcd79c32b8b8cd0fc9369864.
It's from Gentoo commit 794061a3298b5716db015defa7b3e2c583b73980.
It's from Gentoo commit 794061a3298b5716db015defa7b3e2c583b73980.
It's from Gentoo commit 4a4b1c938172b65f3fdb5ecc9b5801555dcb23ce.
It's from Gentoo commit e39e3ae8045d92d376b9ab9d0caa1354d6d13602.
@krnowak krnowak force-pushed the buildbot/weekly-portage-stable-package-updates-2024-05-13 branch from cd69b92 to 75b152e Compare May 31, 2024 16:17
@krnowak
Copy link
Member

krnowak commented Jul 4, 2024

Closing in favor of #2070.

@krnowak krnowak closed this Jul 4, 2024
@krnowak krnowak deleted the buildbot/weekly-portage-stable-package-updates-2024-05-13 branch July 4, 2024 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

update: glib update: tpm2-{tools,tss}
3 participants