Commit Graph

3945 Commits

Author SHA1 Message Date
CBL-Mariner-Bot ac9d1ac234
kernel-hci: Add CVE-2023-1838.nopatch CVE-2023-1252.nopatch CVE-2022-4379.nopatch CVE-2023-1855.nopatch CVE-2022-4095.nopatch CVE-2023-0179.nopatch CVE-2023-30456.nopatch CVE-2023-0386.nopatch CVE-2023-0590.nopatch CVE-2023-1249.nopatch CVE-2022-3707.nopatch CVE-2023-1652.nopatch CVE-2023-25012.nopatch (#5342) 2023-04-20 14:04:27 -04:00
CBL-Mariner-Bot a46accd923
Upgrade tcl to 8.6.13 Fix CVE-2018-25032 (#5323) 2023-04-20 12:54:33 -05:00
Saul Paredes f8c26b9e35
Upgrade nmap to version 7.93 to fix CVE-2018-25032 (#5312)
* nmap: upgrade to latest version

* configure zemap and ndiff

* add back configure macro

* fix openssl build issue

* remove patch from signature file
2023-04-20 10:24:00 -07:00
Elaheh Dehghani 233cc938f8
add mstflint kernel module for secure boot (#5139) 2023-04-20 09:17:26 -07:00
Bala f866f089cf
Fix CVE 2022 37601 on webpack loader-utils integrated with webpack (#5337)
* Fix CVE-2022-37601 by applying patch to a node module shipped with reaper

* Update changelog
2023-04-20 09:58:54 +05:30
Bala cccf68d632
Patch CVE-2021-28235 for etcd packages (#5338)
* Patch CVE-2021-28235 for etcd package

* Update default fuzz value to 1

* Fix typo

* Update changelog
2023-04-20 09:47:30 +05:30
Saul Paredes e3eb99cd0a
Nopatch kernel for CVE-2023-0179, CVE-2023-0386, CVE-2023-0590, CVE-2023-1249, CVE-2023-1252, CVE-2023-1652, CVE-2023-1838, CVE-2023-1855, CVE-2023-25012, CVE-2023-30456, CVE-2022-4379 (#5333)
* nopatch kernel for several cves

* add nopatch
2023-04-19 11:49:13 -07:00
rlmenge df5db4247e
Disable recomputing build-ids for kernel debuginfo packages (#5301)
* Disable regenerating build-ids for kernel debuginfo package

* Add additional comments

* Proprogate change to other kernels
2023-04-19 08:12:46 -07:00
Bala c2f2752f89
Fix CVE-2021-45985 on memcached and ntopng (#5318)
* Fix CVE-2021-45985 on memcached and ntopng

lua source code is integrated inside both of the packages. As lua is
having the CVE-2021-45985, it should be patched before building

* Replace tabs with spaces
2023-04-19 09:39:42 +05:30
CBL-Mariner-Bot 5772299037
kernel-hci: Add CVE-2023-1079.nopatch CVE-2023-1513.nopatch CVE-2022-48424.nopatch CVE-2023-28466.nopatch CVE-2022-48423.nopatch CVE-2023-1281.nopatch (#5328) 2023-04-18 18:10:02 -04:00
CBL-Mariner-Bot 05629834b4
CVE-2023-28466 (#5325) 2023-04-18 13:06:29 -07:00
Anuj Garg e1b6ef53c5
Upgrade k3s to 1.25.8 and 1.26.3 (#5317) 2023-04-18 11:37:47 -07:00
CBL-Mariner-Bot a1147c397b
kernel-hci: Add CVE-2023-1118.nopatch CVE-2023-23004.nopatch CVE-2023-23001.nopatch CVE-2023-23002.nopatch (#5125) 2023-04-18 13:41:22 -04:00
Olivia Crain abb9e9ea1c
Add runtime requirements to gcovr package (#5310) 2023-04-18 10:35:15 -07:00
CBL-Mariner-Bot f398098e36
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.107.1 - branch main - (#5316)
* Kernel upgrade to 5.15.107.1 version

* Apply config changes to ARM64
2023-04-18 10:33:49 -07:00
Bala 72e1fa352b
Add new pkg uchardet to SPECS-EXTENDED (#5208)
* Add new package uchardet to SPECS-EXTENDED

* Update meta files for new package

* Update manifest files

* Remove __cmake_in_source_build macro from leveldb package
2023-04-18 19:25:50 +05:30
Chris PeBenito 9cbb4cf52f
selinux-policy: Add rules for cloud-init and iptables. (#5197)
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com>
2023-04-18 08:52:29 -04:00
SeanDougherty 3f1611a35a
Update chrony.conf in Marketplace to follow time sync recommendations for Linux VMs in Azure (#5314) 2023-04-17 20:33:01 -07:00
Christopher Co 0acce6d9a2
azurevm-packages: Add grubby to package list (#5161)
Some Azure VM extensions, such as the Azure Disk Encryption VM
Extension, need to be able to update the kernel command line parameters
for the extension to function. The method to do this is by utilizing
grubby to update the grubenv block to set the kernelopts= grub
environment variable. And to do this, the grubby package must be already
present on the image prior to the VM extension execution.

So this change adds the grubby package into the azurevm-packages.json
package definition, which is included in every Azure VM image
definition.

grubby requires the grub2 package. Together, these two packkages increase the image footprint by ~34 MB.

$ rpm -qi grubby
Name        : grubby
Version     : 8.40
Release     : 44.cm2
Architecture: x86_64
Install Date: Mon Apr 17 02:41:51 2023
Group       : Unspecified
Size        : 62387
License     : GPLv2+
Signature   : RSA/SHA256, Tue Oct  4 13:04:54 2022, Key ID 0cd9fed33135ce90
Source RPM  : grubby-8.40-44.cm2.src.rpm
Build Date  : Tue Oct  4 09:34:58 2022
Build Host  : e001d47647c4
Vendor      : Microsoft Corporation
URL         : https://github.com/rhinstaller/grubby
Summary     : Command line tool for updating bootloader configs
Description :
This package provides a grubby compatibility script that manages
BootLoaderSpec files and is meant to only be used for legacy compatibility
users with existing grubby users.

$ rpm -qi grub2
Name        : grub2
Version     : 2.06
Release     : 8.cm2
Architecture: x86_64
Install Date: Mon Apr 17 02:41:50 2023
Group       : Applications/System
Size        : 36191957
License     : GPLv3+
Signature   : RSA/SHA256, Sat Jan  7 04:56:35 2023, Key ID 0cd9fed33135ce90
Source RPM  : grub2-2.06-8.cm2.src.rpm
Build Date  : Sat Jan  7 02:45:19 2023
Build Host  : 083a5bc39c7d
Vendor      : Microsoft Corporation
URL         : https://www.gnu.org/software/grub
Summary     : GRand Unified Bootloader
Description :
The GRUB package contains the GRand Unified Bootloader.

Signed-off-by: Chris Co <chrco@microsoft.com>
2023-04-17 17:40:17 -07:00
jslobodzian 09df3ce7fa
Merge pull request #5313 from microsoft/joslobo/cherry-pick-nginx-cve-fix2
Upgrade bundled njs version in nginx to 0.7.12 to fix CVE-2020-19692 and CVE-2020-19695
2023-04-17 16:10:41 -07:00
Olivia Crain d7ce48486c Upgrade bundled njs version in nginx to 0.7.12 to fix CVE-2020-19692, CVE-2020-19695 (#5309) 2023-04-17 16:04:38 -07:00
Daniel McIlvaney bc092b8da7
Add QUICKBUILD flags for fast auto build (#5199)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
2023-04-17 12:01:14 -07:00
Gary Swalling aa5b66d7fb
Enable serial console for ISO installer (#5282)
Enable serial console for ISO installer, both grub.cfg (UEFI) and isolinux.cfg (legacy BIOS).  This allows interactive installation on lab nodes which don't have VGA connected, but only serial console.
2023-04-17 10:47:03 -07:00
Bala aa81802522
Fix CVE-2021-45985 (#5307) 2023-04-17 22:48:25 +05:30
Olivia Crain 0c48ba0e56
Upgrade bundled njs version in nginx to 0.7.12 to fix CVE-2020-19692, CVE-2020-19695 (#5309) 2023-04-17 09:38:43 -07:00
Andrew Phelps 460fa78a08
Merge pull request #5304 from microsoft/anphel/2.0-april7-with-toolkit-rpm-fix
[2.0] Also pass toolchain dir to external package cache fetcher
2023-04-14 18:26:30 -07:00
Pawel Winogrodzki 8333d52a88
Fixing livepatches PR check. 2023-04-14 16:42:32 -07:00
Daniel McIlvaney 7f52f3ddc4 Also pass toolchain dir to external package cache fetcher (#5299) 2023-04-14 19:51:34 +00:00
Andrew Phelps 55548760a9
Rename clang-16 to clang16 and llvm-16 to llvm16 (#5300)
* rename to clang16 and llvm16

* Revert "Add an explicit constraint on llvm-devel < 16.0.0 for bcc, ldd & mesa (#5278)"

This reverts commit 7fd75c9287.
2023-04-14 00:30:51 -07:00
Daniel McIlvaney 5c291aa6f0
Also pass toolchain dir to external package cache fetcher (#5299) 2023-04-13 18:10:26 -07:00
Dallas Delaney a323ac876a
Revert Add kata-containers-cc package (#5246) (#5298)
* Revert Add kata-containers-cc package (#5246)
2023-04-13 17:45:23 -07:00
Riken Maharjan ac55611df0
Remove epoch from some spec files (#5296) 2023-04-13 16:34:38 -07:00
rlmenge 122fcd3a15
Enable CONFIG_HIST_TRIGGERS (#5292)
Add CONFIG_HIST_TRIGGERS to support auoms metrics.
2023-04-13 16:10:50 -07:00
Muhammad Falak R Wani 7fd75c9287
Add an explicit constraint on llvm-devel < 16.0.0 for bcc, ldd & mesa (#5278)
The build for bcc, ldd & mesa does not work with llvm == 16.0.0
Add an explicit constraint to allow build

Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2023-04-13 13:41:54 -07:00
kanikanema fb94500fcf
Enable CONFIG_NVME_TCP and CONFIG_NVME_RDMA as module (#5283)
Updated config for kernel and kernel-hci
2023-04-13 15:32:38 +05:30
Mykhailo Bykhovtsev 578f2bff82
Adding pip requirements and small readme file to toolchain scripts (#5212)
* adding pip requirements file and a readme to toolchain python scripts

* updating requirements file with missed deps and updating readme file

* updating github pipelines to use requirements file to install python dependencies

* Delete README.md

Moved readme file into a wiki page
2023-04-12 16:35:42 -07:00
Rohit Rawat 73dc743bf1
openssl: patch CVE-2023-0465 and CVE-2023-0466 (#5285) 2023-04-12 23:33:14 +05:30
Mykhailo Bykhovtsev 16be1b52c3
Fix uninstallation of InfluxDB package (#5280)
* Attempting to fix influxdb uninstallation issues

* bumping release version and adding changelog

* linting influxdb package
2023-04-11 18:18:53 -07:00
Pawel Winogrodzki c9a8dc735e
Livepatched CVE-2023-1281 in kernel 5.15.94.1-1.cm2. (#5276) 2023-04-11 13:35:03 -07:00
CBL-Mariner-Bot b2f2ce3913
Upgrade libyang to 2.1.55 to fix CVE-2023-26916 (#5265) 2023-04-11 13:03:27 -07:00
CBL-Mariner-Bot edd5c47fe7
Upgrade moby-runc to 1.1.5 to fix CVE-2023-28642, CVE-2023-27561, CVE-2023-25809 (#5253) 2023-04-11 13:03:09 -07:00
Anuj Garg a36e3a38ab
Patch CVE-2023-25173 and CVE-2023-25153 for k3s (#5272)
Co-authored-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2023-04-11 16:52:31 +05:30
AZaugg 5d899b321f
Adding XFS as a root filesystem type (#5198)
* Adding XFS as a root filesystem type

Adding support to provision Mariner with a root filesystem
of type xfs

* Allow Grub to boot XFS

Insert the xfs module allowing grub to boot XFS

* Adding xfs progs to toolchain

To support XFS adding xfsprogs into the mariner build
toolchain

* Addresing PR comments

- Removing xfsprogs from toolchain list
- adding xfsprogs to prereq documentation
2023-04-10 15:25:32 -07:00
Dallas Delaney f383b1c6a8
Add kata-containers-cc package (#5246)
* Add kata-containers-cc package
2023-04-10 13:33:29 -07:00
Anuj Garg c02f10c620
Upgrade k3s to v1.24.6 & add v1.25.5 (#5219)
Co-authored-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2023-04-10 17:36:32 +05:30
Muhammad Falak R Wani 994d951d0e
SPECS-EXTENDED: drop packages that have runtime-unmet dependencies (#5244)
Remove all packages that have unmet runtime deps and
add them one-by-one in subsequent commits and ensure
we do not introduce any runtime unmet dependency.

Following Packages are removed:
- aqute-bnd
- copy-jdk-configs
- dump
- foomatic
- gnome-menus
- httpcomponents-client
- jansi-native
- javapackages-tools-meta
- jsch-agent-proxy
- kdump-anaconda-addon
- koan
- libomp
- libwmf
- migrationtools
- ortp
- parboiled
- perl-Alien-Libxml2
- perl-TestML
- plexus-component-api
- plexus-io
- plymouth
- python-cliff
- python-hacking
- python-keyring
- python-kombu
- python-os-service-types
- python-pycdlib
- python-stestr
- python-stevedore
- python-testrepository
- rust-packaging
- setroubleshoot
- setroubleshoot-plugins
- snakeyaml
- stratis-cli
- subunit
- targetd
- varnish-modules
- varnish
- xdg-user-dirs
- xguest

Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2023-04-10 17:05:20 +05:30
Riken Maharjan f6d8f7386e
Add missing pytorch runtime dependencies (#5247) 2023-04-07 14:22:54 -07:00
Andrew Phelps 8eb9488cca
clang-16 and llvm-16: add new SPECS (#5242)
* add clang-16 and llvm-16

* update licenses

* update clang

* linting
2023-04-07 11:30:13 -07:00
Daniel McIlvaney 004d2b3486
Don't make go modules owned by root (#5176)
* Don't make go modules owned by root
2023-04-07 11:09:34 -07:00
jslobodzian ed786148d4
Merge pull request #5248 from microsoft/joslobo/merge-2.0
Merge 2.0 for April 2023 Update
2023-04-06 22:57:50 -07:00