* Fri Mar 07 2025 Julio Faracco <jfaracco@redhat.com> [6.12.0-61.el10] - af_packet: fix vlan_get_tci() vs MSG_PEEK (CKI Backport Bot) [RHEL-80305] {CVE-2024-57902} - smb: client: fix chmod(2) regression with ATTR_READONLY (Paulo Alcantara) [RHEL-80534] - sched_ext: Fix incorrect autogroup migration detection (CKI Backport Bot) [RHEL-81482] {CVE-2025-21771} - PCI: vmd: Set devices to D0 before enabling PM L1 Substates (Myron Stowe) [RHEL-47437] - PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs (Myron Stowe) [RHEL-47437] - kernel.spec: add missing tools-libs on s390x (Jan Stancek) [RHEL-80626] - arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (CKI Backport Bot) [RHEL-81669] {CVE-2025-21785} - kexec/crash: no crash update when kexec in progress (Mamatha Inamdar) [RHEL-76749] - md/raid*: Fix the set_queue_limits implementations (Nigel Croxon) [RHEL-73721] - md: Fix linear_set_limits() (Nigel Croxon) [RHEL-73721] - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime (Nigel Croxon) [RHEL-73721] - md/md-linear: Fix a NULL vs IS_ERR() bug in linear_add() (Nigel Croxon) [RHEL-73721] - md/md-bitmap: move bitmap_{start, end}write to md upper layer (Nigel Croxon) [RHEL-73721] - md/raid5: implement pers->bitmap_sector() (Nigel Croxon) [RHEL-73721] - md: add a new callback pers->bitmap_sector() (Nigel Croxon) [RHEL-73721] - md/md-bitmap: remove the last parameter for bimtap_ops->endwrite() (Nigel Croxon) [RHEL-73721] - md/md-bitmap: factor behind write counters out from bitmap_{start/end}write() (Nigel Croxon) [RHEL-73721] - md: Replace deprecated kmap_atomic() with kmap_local_page() (Nigel Croxon) [RHEL-73721] - md/raid10: Atomic write support (Nigel Croxon) [RHEL-73721] - md/raid1: Atomic write support (Nigel Croxon) [RHEL-73721] - md/raid0: Atomic write support (Nigel Croxon) [RHEL-73721] - block: Support atomic writes limits for stacked devices (Nigel Croxon) [RHEL-73721] - md/raid5: Increase r5conf.cache_name size (Nigel Croxon) [RHEL-73721] - md/raid10: Handle bio_split() errors (Nigel Croxon) [RHEL-73721] - md/raid1: Handle bio_split() errors (Nigel Croxon) [RHEL-73721] - md/raid0: Handle bio_split() errors (Nigel Croxon) [RHEL-73721] - md/raid5: Wait sync io to finish before changing group cnt (Nigel Croxon) [RHEL-73721] - md/md-bitmap: Add missing destroy_work_on_stack() (Nigel Croxon) [RHEL-73721] - md/raid5: don't set Faulty rdev for blocked_rdev (Nigel Croxon) [RHEL-73721] - md/raid10: don't wait for Faulty rdev in wait_blocked_rdev() (Nigel Croxon) [RHEL-73721] - md/raid1: don't wait for Faulty rdev in wait_blocked_rdev() (Nigel Croxon) [RHEL-73721] - md/raid1: factor out helper to handle blocked rdev from raid1_write_request() (Nigel Croxon) [RHEL-73721] - md: don't record new badblocks for faulty rdev (Nigel Croxon) [RHEL-73721] - md: don't wait faulty rdev in md_wait_for_blocked_rdev() (Nigel Croxon) [RHEL-73721] - md: add a new helper rdev_blocked() (Nigel Croxon) [RHEL-73721] - md/raid5-ppl: Use atomic64_inc_return() in ppl_new_iounit() (Nigel Croxon) [RHEL-73721] - RDMA/mlx5: Fix a WARN during dereg_mr for DM type (Benjamin Poirier) [RHEL-41204] - arm64: mm: Fix zone_dma_limit calculation (Luiz Capitulino) [RHEL-71568] - uki: enable FIPS mode (Vitaly Kuznetsov) [RHEL-80149] Resolves: RHEL-47437, RHEL-73721, RHEL-76749, RHEL-80305, RHEL-80534, RHEL-80626, RHEL-81482, RHEL-81669 Signed-off-by: Julio Faracco <jfaracco@redhat.com>
54 lines
1.4 KiB
Plaintext
54 lines
1.4 KiB
Plaintext
# generic + compressed please
|
|
hostonly="no"
|
|
compress="xz"
|
|
|
|
# VMs can't update microcode anyway
|
|
early_microcode="no"
|
|
|
|
# modules: basics
|
|
dracutmodules+=" dracut-systemd i18n shutdown "
|
|
|
|
# modules: storage support
|
|
dracutmodules+=" dm lvm rootfs-block fs-lib "
|
|
|
|
# modules: tpm and crypto
|
|
dracutmodules+=" crypt crypt-loop tpm2-tss systemd-pcrphase "
|
|
|
|
# dracut >= 102 separated systemd-cryptsetup into its own module
|
|
CSMODULE=`dracut --list-modules --no-kernel | grep '^systemd-cryptsetup$'`
|
|
dracutmodules+=" $CSMODULE "
|
|
|
|
# modules: support root on virtiofs
|
|
dracutmodules+=" virtiofs "
|
|
|
|
# modules: use sysext images (see 'man systemd-sysext')
|
|
dracutmodules+=" systemd-sysext "
|
|
|
|
# modules: root disk integrity protection
|
|
dracutmodules+=" systemd-veritysetup "
|
|
|
|
# modules: FIPS
|
|
dracutmodules+=" fips "
|
|
# FIPS mode requires early crypto drivers test
|
|
drivers+=" =crypto "
|
|
|
|
# drivers: virtual buses, pci
|
|
drivers+=" virtio-pci virtio-mmio " # qemu-kvm
|
|
drivers+=" hv-vmbus pci-hyperv " # hyperv
|
|
drivers+=" xen-pcifront " # xen
|
|
|
|
# drivers: storage
|
|
drivers+=" ahci nvme sd_mod sr_mod " # generic
|
|
drivers+=" virtio-blk virtio-scsi " # qemu-kvm
|
|
drivers+=" hv-storvsc " # hyperv
|
|
drivers+=" xen-blkfront " # xen
|
|
|
|
# root encryption
|
|
drivers+=" dm_crypt "
|
|
|
|
# root disk integrity protection
|
|
drivers+=" dm_verity overlay "
|
|
|
|
# filesystems
|
|
filesystems+=" vfat ext4 xfs overlay "
|