Commit Graph

861 Commits

Author SHA1 Message Date
Eduard Abdullin
d0138ba04f Debrand for AlmaLinux
Build btrfs module
2025-07-29 17:19:31 +00:00
Leo Sandoval
33ce16660b Set correctly the memory attributes for the kernel PE sections
Resolves: #RHEL-97086

Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-07-28 13:16:55 -06:00
Eduard Abdullin
937af33ec1 Debrand for AlmaLinux
Build btrfs module
2025-07-17 01:41:20 +00:00
Leo Sandoval
78ed8c744d mm: do not update mem attrs even if EFI protocol is present
A temporal workaround while a real fix is being elaborated.

Resolves: #RHEL-97086

Signed-off-by: Gerd Hoffman <ghoffman@redhat.com>
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-07-15 14:43:49 -06:00
f51fe75d56 Build btrfs module 2025-06-10 13:51:35 +00:00
Leo Sandoval
079a0bd238 Bump version (see CS-2896)
Resolves: #RHEL-94342
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-06-06 09:26:53 -06:00
Eduard Abdullin
e41d0dfbc1 Debrand for AlmaLinux 2025-06-04 01:38:57 +00:00
Leo Sandoval
2be0734e9b Handle special kernel parameter characters properly
Resolves: #RHEL-94342
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-06-02 16:20:19 -06:00
Eduard Abdullin
9c2169a04c Debrand for AlmaLinux 2025-05-15 01:40:15 +00:00
Nicolas Frayer
0127cb7cb1 sbat: bump grub sbat for new shim release
Resolves: #RHEL-91277
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-05-14 11:30:00 +02:00
Eduard Abdullin
ca2d22c06b Debrand for AlmaLinux 2025-05-14 01:39:53 +00:00
Nicolas Frayer
81cae7e227 sbat: add new sbat entry for centos
Resolves: #RHEL-91146
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-05-13 16:38:36 +02:00
Eduard Abdullin
57d187df94 Debrand for AlmaLinux 2025-04-19 01:41:35 +00:00
Andrea Bolognani
bdb6399fe8 Fix riscv64 build
Resolves: RHEL-85987

Signed-off-by: Andrea Bolognani <abologna@redhat.com>
2025-04-17 01:32:52 +02:00
Eduard Abdullin
8962dff37a Debrand for AlmaLinux 2025-04-16 01:42:29 +00:00
Nicolas Frayer
d002e804dd ppc/mkimage: SBAT support on powerpc
Resolves: #RHEL-87420
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-04-15 15:54:33 +02:00
Eduard Abdullin
ec87815ca3 Debrand for AlmaLinux 2025-04-09 01:42:44 +00:00
Marta Lewandowska
5b54c60e8c 99-grub-mkconfig.install: Disable BLS and run grub2-mkconfig when GRUB_ENABLE_BLSCFG is disable
Resolves: #RHEL-86261

Signed-off-by: Marta Lewandowska <mlewando@redhat.com>
Reviewed-by: Leo Sandoval <lsandova@redhat.com>
2025-04-07 14:22:57 -06:00
Eduard Abdullin
480d6cce5b Debrand for AlmaLinux 2025-03-26 01:40:21 +00:00
Nicolas Frayer
d23765b1e8 ieee1275/ofnet: Fix grub_malloc() removed after added safe
Related: #RHEL-80073
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-03-25 14:49:31 +01:00
Eduard Abdullin
99e0fe97fc Debrand for AlmaLinux 2025-03-19 01:40:59 +00:00
Nicolas Frayer
5f77cf3173 powerpc: increase MIN RMA size for CAS negotiation
Resolves: #RHEL-76429
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-03-18 14:43:02 +01:00
Eduard Abdullin
8868949a4d Debrand for AlmaLinux 2025-03-12 01:40:01 +00:00
Leo Sandoval
95e08eb027 Remove NTFS attribute verification patch
The removed patch was part of the CVE patches ported recently into RHEL but
is causing segfaults on dual boot (Windows & RHEL) systems when generating the
grub configuration with the grub2-mkconfig tool. At some point the same patch
will come back with the corresponding fix but for the time being, it is removed.

Related: RHEL-80686

Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-03-11 10:29:02 -06:00
Eduard Abdullin
bba9c0f0f0 Debrand for AlmaLinux 2025-02-27 01:41:13 +00:00
Nicolas Frayer
b621d47266 Bump release to trigger signing tools
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-02-26 15:29:45 +01:00
Nicolas Frayer
0f8974ea55 fs/ext2: Rework out-of-bounds read for inline and external extents
Related: #RHEL-80686
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-02-26 12:19:46 +01:00
Vitaly Kuznetsov
61e8038539 99-grub-mkconfig: Avoid disabling BLS usage for Xen HVM VMs
Xen PV and PVH guest use direct kernel boot and may use 'pygrub' tool to
parse guest's grub config. The tool is incompatible with BLS and thus
99-grub-mkconfig.install disables it. The problem is observed with HVM
guests which are 'normal' VMs and don't require pygrub compatibility. E.g.
legacy AWS instance types are of this kind. Disabling BLS for them is
undesired and unjustified. Luckily, kernel driver for Xen provides
'/sys/hypervisor/guest_type' interface telling us which type of guest are
we running in.

Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>
2025-02-26 12:13:24 +01:00
Eduard Abdullin
fc029ed5d4 Debrand for AlmaLinux 2025-02-26 01:39:34 +00:00
Leo Sandoval
b9f070c2f2 Add Several CVE fixes
Resolves: CVE-2024-45781 CVE-2024-45783 CVE-2024-45778
Resolves: CVE-2024-45775 CVE-2024-45780 CVE-2024-45774
Resolves: CVE-2025-0690 CVE-2025-1118 CVE-2024-45782
Resolves: CVE-2025-0624 CVE-2024-45779 CVE-2024-45776
Resolves: CVE-2025-0622 CVE-2025-0677
Resolves: #RHEL-80691
Resolves: #RHEL-80690
Resolves: #RHEL-80689
Resolves: #RHEL-80687
Resolves: #RHEL-80686

Signed-off-by: Leo Sandoval <lsandova@redhat.com>
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-02-25 11:59:31 -06:00
eabdullin
5e81c9eb0d Merge branch 'c10s' into a10s 2025-01-24 13:26:17 +03:00
Leo Sandoval
c17ad7254d fix pending SAST issues
Resolves: #RHEL-50504

Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-01-22 17:05:40 -06:00
Leo Sandoval
ff6d9c809c term/ns8250-spcr: return if redirection is disabled
Compared to previous commit, this is a better approach to handle SPCR null base
address indicating no redirection, doing the null check on the caller instead of
the callee.

Resolves: #RHEL-68622
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-01-17 11:25:47 -06:00
eabdullin
a517862d5c Merge branch 'c10s' into a10s 2025-01-16 11:59:02 +03:00
Leo Sandoval
4052952894 term/ns8250: return in case of a null SPCR base addresses
Resolves: #RHEL-68622
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2025-01-13 12:04:13 -06:00
Nicolas Frayer
6f919c8415 fs/xfs: fix large extent counters incompat feature support
Resolves: #RHEL-68390
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2025-01-09 17:52:49 +01:00
eabdullin
a26ed1e662 Merge branch 'c10s' into a10s 2025-01-08 12:46:02 +03:00
Michal Sekletar
05eb032a32 Remove BLS fake config on kernel removal
Resolves: #RHEL-59557
Signed-off-by: Michal Sekletar <msekleta@redhat.com>
Reviewed-by: Leo Sandoval <lsandova@redhat.com>
Reviewed-by: Marta Lewandowska <mlewando@redhat.com>
2024-12-09 13:34:57 -06:00
Leo Sandoval
8812e31e42 acpi: Fix out of bounds access in grub_acpi_xsdt_find_table()
Resolves: #RHEL-68690
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2024-12-09 10:06:32 -06:00
28f9613717 Merge tag 'imports/c10s/grub2-2.12-1.el10' into a10s 2024-12-09 16:35:36 +03:00
Leo Sandoval
adaa841fca 10_linux.in: escape semicolon and ampersand on BLS upddate
Resolves: #RHEL-68531
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2024-11-21 12:48:34 -06:00
Leo Sandoval
f9ffaac36e Rebased to release grub-2.12
Resolves: #RHEL-15032

Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2024-11-07 09:45:00 -06:00
Troy Dawson
d5c5bf4a63 Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
2024-10-29 08:28:59 -07:00
f4d8802bb4 Merge branch 'c10s' into a10s 2024-09-26 13:24:06 +03:00
Leo Sandoval
20db98c9e3 posttrans: condition EFI_HOME/grub.cfg cmds if stub is present
Resolves: #RHEL-59796
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2024-09-23 11:19:04 -06:00
Nicolas Frayer
742532ab73 grub.cfg: Fix an issue when doing a major version upgrade
Related: #RHEL-56733
Signed-off-by: Marta Lewandowska <mlewando@redhat.com>
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2024-09-23 14:33:04 +02:00
Nicolas Frayer
1022bec884 spec: Added more code for the previous CVE fix
Related: #RHEL-56733
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2024-09-23 14:31:55 +02:00
Nicolas Frayer
008b689173 aarch64/macros: Re-added flags that disappeared with previous commit
Related: #RHEL-58821
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2024-09-18 17:56:57 +02:00
Nicolas Frayer
c69e56f2af aarch64/macros: Build gnulib with -mbranch-protection=standard
Resolves: #RHEL-58821
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
2024-09-13 09:33:04 +02:00
Leo Sandoval
5e22405b1c grub.cfg: Fix rpm grub.cfg permission and verification issues
Fix the rpm verificaton issues. On the other hand, 2.06-121 [1]
introduced a change on grub2-mkconfig where it prevents overwritting
`${EFI_HOME}/grub.cfg` with side effects on the `%posttrans`
scriptlet, where it tries to recreate it in case this file does not
exist but due to [1] the `${EFI}/grub.cfg` file would never be
created. Fix the `%posttrans` code with the logic but applied to
${GRUB_HOME}/grub.cfg. On the same scriplet, make sure
${EFI_HOME}/grub.cfg is present before grepping into it.

[1] https://pkgs.devel.redhat.com/cgit/rpms/grub2/commit/?h=rhel-10-main&id=9c6e5cf6c8e597efbf6a10399371789fddafac12

Resolves: #RHEL-56918
Signed-off-by: Leo Sandoval <lsandova@redhat.com>
2024-09-03 16:14:28 -06:00