Commit Graph

78 Commits

Author SHA1 Message Date
Nicolas Frayer
8378a93e60 grub2-mkconfig: don't overwrite BLS cmdline if BLSCFG is true
Resolves: #2203203
Resolves: #2212320
Resolves: #2221543
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2023-07-25 12:02:43 +02:00
Nicolas Frayer
5dc4855520 build with baseline ISA flags
Resolves: #2215860
Signed-off-by: Florian Weimer <fweimer@redhat.com>
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2023-07-20 17:03:44 +02:00
Nicolas Frayer
baa6c11af8 efi/http: change uint32_t to uintn_t
Resolves: #2207851
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2023-06-08 11:10:00 +02:00
Nicolas Frayer
8bb1eea054 kern/ieee1275/init: sync vec5 patchset with upstream
Resolves: #2183939
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2023-06-01 09:29:57 +02:00
Nicolas Frayer
b9c80be152 util: Enable default kernel for updates
Resolves: #2184069
Signed-off-by: Marta Lewandowska <mlewando@redhat.com>
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2023-05-30 18:10:51 +02:00
Javier Martinez Canillas
f2e9faa56a 20-grub-install: Explicitly check '+debug' suffix for debug kernels
The kernel-install script is also used to install kernels when built from
source using the `make install` target.

And if this source contains modifications, a '+' is added as suffix by the
scripts/setlocalversion if no LOCALVERSION was set in the kernel config.

This confuses the grub2 kernel-install plugin, since it currently assumes
that any kernel that contain a version with a '+' suffix is a debug kernel.

But the match is too greedy, just having '+debug' should be enough to check
whether the kernel to install is a debug kernel or not.

Related: #2184069
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
2023-05-30 18:09:45 +02:00
Robbie Harwood
05b99a3203 rpminspect: fix ignore syntax and migrate
Resolves: #2026579
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-21 10:53:03 -05:00
Robbie Harwood
36401863be ppc64le sysfs and mm update
Resolves: #2026579
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-20 17:22:34 +00:00
Robbie Harwood
611ca8bf3e rpminspect: add a reduced elf ignorelist
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-16 13:16:45 -05:00
Robbie Harwood
861fb30b3e Sync patches with Fedora
Resolves: #2007427
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-16 09:51:24 -05:00
Robbie Harwood
5ad247ff66 ppc64le: sync cas/tpm patchset with upstream
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-08 20:08:58 +00:00
Robbie Harwood
d3f33bc682 rpminspect: ignore debuginfo
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-06 18:17:32 -05:00
Robbie Harwood
1149c5b9c8 ppc64le: cas5, take 3
Resolves: #2153071
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-06 20:31:54 +00:00
Robbie Harwood
433335e50c Pull in allocator fixes from upstream
Resolves: #2156419
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-02-01 19:51:45 +00:00
Robbie Harwood
501956fdc0 ppc64le: disable mdraid < 1.1
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-01-31 21:13:28 +00:00
Robbie Harwood
fcdb04c11c Fix grub-probe isuses in previous commit
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-01-27 20:52:00 +00:00
Robbie Harwood
9c7afa3d14 ppc64le: update signed media fixes
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-01-27 19:19:39 +00:00
Robbie Harwood
80718e98fa ppc64le: fix issues using core.elf on boot media
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2023-01-13 20:30:06 +00:00
Robbie Harwood
1395eb50d1 ppc64le: fix lpar cas5
Resolves: #2153071
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-12-14 19:37:46 +00:00
Robbie Harwood
77d588fe51 Bless the ofnet module down in ppc64le
Resolves: #2143420
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-11-21 20:24:50 +00:00
Robbie Harwood
3bdba954d6 Bump SBAT
Resolves: CVE-2022-2601
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-11-08 11:21:19 -05:00
Robbie Harwood
f2a26f5bbb Font CVE fixes
Resolves: CVE-2022-2601
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-11-03 19:34:00 +00:00
Robbie Harwood
525d9dc867 gating: re-enable all tests
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-11-01 14:22:57 -04:00
Robbie Harwood
f6015fa651 TDX measurement to RTMR
Resolves: #1981487
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-10-28 13:06:11 -04:00
Robbie Harwood
1db6b68958 x86-efi: Fix an incorrect array size in kernel allocation
Resolves: #2031289
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-10-12 19:44:29 +00:00
Robbie Harwood
c1ebf6e8ba Sync /etc/kernel/cmdline generation with 2.06-52.fc38
Resolves: #1969362
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-25 17:31:05 +00:00
Robbie Harwood
5af1faa717 ieee1275: implement vec5 for cas negotiation
Resolves: #2121192
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-25 15:41:57 +00:00
Robbie Harwood
d449759abf Skip rpm mtime verification on likely-vfat filesystems
Resolves: #2047979
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-15 21:04:30 +00:00
Robbie Harwood
b3aed40f50 Generate BLS snippets during mkconfig
Resolves: #1969362
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-11 16:26:51 +00:00
Robbie Harwood
8f1a5b9955 Rest of kernel allocator fixups
Resolves: #2108456
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-02 14:42:02 +00:00
Robbie Harwood
217d6ad6ef Kernel allocator fixups
Resolves: #2108456
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-02 13:48:57 +00:00
Robbie Harwood
d938855e21 Rebuild against new ppc64le key
Resolves: #2074761
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-07-18 19:44:56 +00:00
Robbie Harwood
836032bc4e Rebuild against new ppc64le key
Resolves: #2074761
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-07-18 19:03:10 +00:00
Robbie Harwood
49f16a61fd Bump release
Resolves: #2051314
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-06-28 19:08:57 -04:00
Robbie Harwood
d1284519d3 Bless the TPM module on ppc64le
Resolves: #2051314
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-06-28 22:48:20 +00:00
Robbie Harwood
42b3050a74 CVE fixes for 2022-05-24
CVE-2022-28736 CVE-2022-28735 CVE-2022-28734 CVE-2022-28733
CVE-2021-3697 CVE-2021-3696 CVE-2021-3695
Resolves: #2070688

Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-06-03 14:09:47 -04:00
Robbie Harwood
1b83bb93b8 ppc64le: make ofdisk_retries optional
Resolves: #2070725
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-05-17 16:54:01 +00:00
Robbie Harwood
4ff57c1cdd ppc64le: CAS improvements, prefix detection, and vTPM support
Resolves: #2068281
Resolves: #2051314
Resolves: #2076798
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-05-04 18:29:29 +00:00
Robbie Harwood
f0e4b8c683 Fix rpm verification report on grub.cfg permissions
Resolves: #2076322
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-05-04 17:31:36 +00:00
Robbie Harwood
e3753ed4c2 First 9.1 build; no changes from 9.0
- Fix initialization on efidisk patch
- Re-run signing with updated redhat-release

Resolves: #2062874
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-05-04 12:06:10 -04:00
Robbie Harwood
01f68549dc Enable connectefi module
Resolves: #2049219
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-28 19:16:25 +00:00
Robbie Harwood
82f85447d7 Add efidisk/connectefi patches
Resolves: #2049219
Resolves: #2049220
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-24 22:24:21 +00:00
Robbie Harwood
d08fc02f2d Re-arm GRUB_ENABLE_BLSCFG=false
Resolves: #2018331
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-18 21:21:20 +00:00
Robbie Harwood
bfdc50ae19 Stop building unsupported 32-bit UEFI stuff
Resolves: #2038401
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-18 20:38:05 +00:00
Brian Stinson
ea946fe76d Require Secure Boot certs based on architecture
Resolves: #2049214

Signed-off-by: Brian Stinson <bstinson@redhat.com>
2022-02-16 15:55:59 -06:00
Brian Stinson
726ced531a Conditionalize Secure Boot settings per architecture
Related: rhbz#2049214

Signed-off-by: Brian Stinson <bstinson@redhat.com>
2022-02-16 15:13:14 -06:00
Robbie Harwood
2ab799de70 Attempt to fix ppc64le signing bugs in previous change
Resolves: #2049214
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-16 19:05:03 +00:00
Robbie Harwood
c4d20133ef Bump spec for previous two signing commits
Resolves: #2049214
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-16 12:41:39 -05:00
Brian Stinson
3f01b520d0 Point secureboot certs at the paths defined by the *-sb-certs packages
Resolves: rhbz#2049214

Signed-off-by: Brian Stinson <bstinson@redhat.com>
[rharwood: commit message, conditional fix]
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-02-16 12:39:39 -05:00
Brian Stinson
ac3d500683 Switch grub2 back to single-signing for Secure Boot
Related: rhbz#2049214

Signed-off-by: Brian Stinson <bstinson@redhat.com>
2022-02-15 13:00:50 -06:00