Граф коммитов

5101 Коммитов

Автор SHA1 Сообщение Дата
nicolas guibourge 08103edbbe
Adress CodeQL issue due to rebranding (#8774)
Co-authored-by: CBL-Mariner Servicing Account <cblmargh@microsoft.com>
2024-04-12 07:14:50 -07:00
Archana Choudhary 7f16bb9fb2
[kata-cc] kernel-uvm: enable CIFS modules (#8589) 2024-04-12 15:35:13 +05:30
ndubchak 77450ba62a
Add patch to nodejs to fix CVE-2024-27983 (#8760) 2024-04-11 16:48:51 -07:00
Mandeep Plaha f7dde9a037
add image-id file in etc dir (#8663) 2024-04-11 10:20:19 -07:00
CBL-Mariner-Bot 28c2f2ee66
[AUTO-CHERRYPICK] Upgrade cri-o to 1.21.7 for CVE-2022-0811, add patch for CVE-2022-1708 - branch main (#8757)
Co-authored-by: Adithya J <adithyajay@gmail.com>
2024-04-11 14:17:35 +05:30
CBL-Mariner-Bot 00af5fe40b
[AUTO-CHERRYPICK] Update packer to 1.10.1 to address CVE-2023-49569 - branch main (#8758)
Co-authored-by: Sumynwa <sumsharma@microsoft.com>
2024-04-11 14:16:47 +05:30
jslobodzian 87bd8ada7b
Remove nodejs as it's End of Life (#8571) 2024-04-10 09:20:12 -07:00
Mitch Zhu 8f975bc73a
moby-containerd-cc: remove obsolete build dependency (#8737) 2024-04-09 10:29:34 -07:00
Sumynwa a17f261f7d
Bump conmon version to 2.1.2 for CVE-2022-1708 (#8714) 2024-04-08 11:30:30 +05:30
CBL-Mariner-Bot f8509ca275
[AUTO-CHERRYPICK] [cherry-pick] Andrew's Change for Perl CVEs (CVE-2023-47100, CVE-2023-31484, CVE-2023-31486) - branch main (#8718)
Co-authored-by: Riken Maharjan <106988478+rikenm1@users.noreply.github.com>
2024-04-05 14:45:49 -07:00
CBL-Mariner-Bot 1ee95f3644
[AUTOPATCHER-CORE] Upgrade telegraf to 1.29.4 CVE-2023-50658 (#8668)
Co-authored-by: Aurélien Bombo <abombo@microsoft.com>
2024-04-05 11:27:36 -07:00
CBL-Mariner-Bot a9238ce9f6
[AUTOPATCHER-CORE] Upgrade opa to 0.63.0 CVE-2023-45142 (#8646) 2024-04-05 10:32:02 -07:00
Rachel Menge 7592f87700
Remove Kernel Required Configs Check (#8661)
This check was added to alert if kernel configs with known required values have been changed to undesired values or removed. Additionally it would alert developers to update the json with justification to help with future checks.

This check is no longer needed now that kernel maintainers are required on each PR review for configs. Additionally, the check caused noise and failed frequently. Therefore, remove.
2024-04-04 17:27:36 -07:00
Pawel Winogrodzki 735fb25e28
Moved distroless cert dependencies out of the meta package `distroless-packages`. (#8651) 2024-04-04 14:51:53 -07:00
Lanze Liu ed1593e99f
Cherry-pick delta for Overlay Dracut Module from 3.0-dev to main. (#8665)
Co-authored-by: lanzeliu <lanzeliu@microsoft.com>
2024-04-03 17:26:47 -07:00
Betty 2beb9b4cd1
Fix the date in logs (#8687)
Co-authored-by: Betty Lakes <bettylakes@microsoft.com>
2024-04-03 13:42:59 -07:00
CBL-Mariner-Bot ec34e6f21f
[AUTOPATCHER-CORE] Upgrade fluent-bit to 2.2.2 CVE-2024-23722 (#8684)
Co-authored-by: Aurélien Bombo <abombo@microsoft.com>
2024-04-03 13:33:35 -07:00
Pawel Winogrodzki d85b1009d6
Fixing toolchain rebuilds for delta builds. (#8680) 2024-04-03 09:02:32 -04:00
Betty 6aa5d9b0eb
Upgrade emacs to 29.3 to fix CVE-2024-30202, CVE-2024-30204, CVE-2024-30205 (#8678)
Co-authored-by: Betty Lakes <bettylakes@microsoft.com>
2024-04-02 22:56:15 -07:00
Mandeep Plaha 5d9f282bcf
Revert "explicitly add libgcc as a Requires to distroless base (#8538)" (#8645) 2024-04-01 13:55:05 -07:00
Adub17030MS 533f23ba1e
Update expat changelog (#8601)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
2024-04-01 13:42:42 -07:00
Cameron E Baird 40cde928e9
kernel-mshv: buildrequire grub2-rpm-macros to fix macro expansion (#8636) 2024-04-01 11:33:26 -07:00
CBL-Mariner-Bot 853ffb8e34
[AUTOUPGRADE-CORE] Upgrade ca-certificates Msft cert change (#8606) 2024-04-01 11:24:49 -07:00
Rohit Rawat 8098d25c1f
libreswan: Upgrade to 4.14 (#8630) 2024-04-01 22:31:18 +05:30
jslobodzian 7be162e0c7
Bump Mariner Release for April 2024 update (#8627) 2024-03-30 08:48:06 -04:00
jslobodzian b833ace827
Revert "[2.0] dhcp/dhclient.conf: add option rfc3442-classless-static… (#8587) 2024-03-30 08:47:47 -04:00
Adit Jha c2337a9079
open-vm-tools: patch to address CVE-2023-34058 & CVE-2023-34059 (#8616) 2024-03-29 12:39:19 -07:00
CBL-Mariner-Bot f4d94437f9
[AUTO-CHERRYPICK] Add CVE-2023-5574, CVE-2023-5367 & CVE-2023-5380 patch to xorg-x11-server ver 1.20.10 - branch main (#8609)
Co-authored-by: Alberto Perez <aperezguevar@microsoft.com>
2024-03-29 10:37:54 -05:00
CBL-Mariner-Bot c749e02944
[AUTO-CHERRYPICK] Upgrade expat to 2.6.2 CVE-2023-52425 and CVE-2024-28757 - branch main (#8563)
Co-authored-by: Adub17030MS <110563293+Adub17030MS@users.noreply.github.com>
2024-03-28 15:11:36 -07:00
CBL-Mariner-Bot d838a1da58
[AUTO-CHERRYPICK] Upgrade python to 3.9.19: address CVE-2023-6597 and other security concerns - branch main (#8592)
Co-authored-by: binujp <binujp@gmail.com>
2024-03-28 14:23:16 -07:00
CBL-Mariner-Bot d7b8822cb3
[AUTO-CHERRYPICK] Add patch to package qt5-qtbase to address CVE-2022-25643 - branch main (#8588)
Co-authored-by: Alberto Perez <aperezguevar@microsoft.com>
2024-03-28 13:26:45 -05:00
Adit Jha b8f18fae47
libvirt: Address Medium CVE-2024-2496 (#8567) 2024-03-28 10:06:37 -07:00
Mandeep Plaha b410ace4a0
move busybox build from core to golden containers (#8561) 2024-03-28 10:02:03 -07:00
CBL-Mariner-Bot 136593e8b6
[AUTOPATCHER-kernel] Kernel upgrade to version 5.15.153.1 - branch main (#8586)
Co-authored-by: Rachel Menge <rachelmenge@microsoft.com>

This update contains backports for 
ovl: let helper ovl_i_path_real() return the realinode [upstream b2dd05f]
ovl: fix null pointer dereference in ovl_permission() [upstream 1a73f5b]
2024-03-28 09:49:19 -07:00
CBL-Mariner-Bot ad9d9ebb91
[AUTO-CHERRYPICK] Limited cascading rebuilds for the fast-track PR check to 1. - branch main (#8581)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
2024-03-27 16:02:50 -07:00
CBL-Mariner-Bot 6cd3118bbd
[AUTO-CHERRYPICK] unixODBC: Address HIGH CVE-2024-1013 - branch main (#8568)
Co-authored-by: Adit Jha <111916775+aditjha-msft@users.noreply.github.com>
2024-03-26 19:41:21 -07:00
Rachel Menge 2bf08ea7cf
Upgrade kernel to 5.15.151.2 (#8557)
This contains an LSG backported patch [27b7b5779b95fe7be1dd71e3b193bfcf6c3f16b1] for hv_netvsc. Note that all versions afterward (>=5.15.152.1) contain this patch within the stable source
2024-03-26 16:14:33 -07:00
CBL-Mariner-Bot 9bf97c0881
[AUTO-CHERRYPICK] Enabled ccache and artifact suffixes for fast-track PR check - branch main (#8550)
Co-authored-by: Pawel Winogrodzki <pawelwi@microsoft.com>
2024-03-26 14:18:56 -07:00
Rachel Menge 9f72507e20
Address kernel CVE-2023-35827 (#8558) 2024-03-26 10:49:06 -07:00
Andrew Phelps 392fadb5a2
Cython: skip long tests (#8546) 2024-03-25 14:57:14 -07:00
Riken Maharjan 08869dadc1
Update guava to 32.1.3 in Javapackages-bootstrap (#8524) 2024-03-25 13:00:26 -07:00
Mandeep Plaha 461159897d
explicitly add libgcc as a Requires to distroless base (#8538) 2024-03-25 11:23:30 -07:00
Pawel Winogrodzki 4500649bbf
Upgraded `etcd` to version 3.5.12. (CP: #8477) (#8530) 2024-03-25 10:49:08 -07:00
Muhammad Falak R Wani 9c0adcb238
msft-golang: upgrade version 1.21.6 -> 1.21.8 (#8516)
Changelog: https://github.com/microsoft/go/releases/tag/v1.21.8-3
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2024-03-23 10:23:56 +05:30
Cameron E Baird 6adb0e682b
Address kernel CVEs 2023-52434, 2023-52435 (#8527) 2024-03-22 18:45:03 -07:00
Lanze Liu 44508c999d
Exclude overlayfs module from main dracut package. (#8529)
Co-authored-by: lanzeliu <lanzeliu@microsoft.com>
2024-03-22 16:52:37 -07:00
Minghe Ren c6d069f689
add patch for cloud-init pkg install error (#8422)
Co-authored-by: minghe <rmhsawyer>
2024-03-22 10:52:46 -07:00
Adub17030MS 110c93fa0b
nodejs and nodejs18: Adding patch for CVE-2024-22025 (#8483) 2024-03-21 09:24:37 -07:00
Muhammad Falak R Wani e90170939d
libvirt: address CVE-2024-1441 (#8447)
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
2024-03-21 11:18:09 +05:30
Christopher Co 7dea67d5c1
fix: introduce mariner_2_initrd_use_suffix kdump.conf option (#6479)
There are two issues. First, our default kdump configuration causes the
kdump service to use the host's default initrd as the crashkernel
environment. This can lead to issues when the default initrd size is
larger than the reserved memory for the crash kernel, which is set via
kernel command line at boot time.

It is common to have the kdump service instead rebuild a minimal
host-specific initrd specifically for the crashkernel environment.

To change this behavior, comment out force_no_rebuild 1 from kdump.conf.

After doing this, a second issue was discovered where the system would
enter the crashkernel environment when a kernel panic occurred, and
successfully collect the crash dump, but upon reboot back to the normal
host OS, the system would no longer boot.

This behavior was root caused to an issue in our kdumpctl command where
the TARGET_INITRD was pointing to our default host initrd, thus when the
kdump service would regenerate the minimal host-specific initrd, this
new initrd would overwrite the host's normal initrd, therefore leading
to failed normal boot.

Since Mariner 2.0 already has a precident to use the host system's initrd,
we need to still preserve this behavior by default, but allow users to opt
in to the better option.

Therefore, this change introduces a new "mariner_2_initrd_use_suffix"
option. When set, the option appends "kdump" suffix to TARGET_INITRD path,
which means the host system's initrd is no longer being targeted for
kdump.

This change also adds a guard-rail in kdumpctl to ensure both
"force_no_rebuild" and "mariner_2_initrd_use_suffix" are not set, otherwise
the kdump will fail to arm correctly since kdump will not be able to locate
the host's initrd.

When compressed kdump collection is enabled, vmcore data is now being
stored in /var/crash/-- directory using the
kdump-lib-initramfs.sh script. Specifically
/var/crash/-<date +%Y-%m-%d-%T>

Previously, the vmcore data was being saved from kdumpctl, which was
storing vmcores in /var/crash/-. Specifically

/var/crash/<date +%Y-%m-%d-%H:%M>

Since there could be automation already in place that expects the older
format, adjust the newer compressed kdump version to align with the older
/var/crash/- directory naming.

Signed-off-by: Chris Co <chrco@microsoft.com>
2024-03-20 15:57:48 -07:00