Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Weekly portage-stable package updates 2025-01-13 #2580

Merged
merged 265 commits into from
Jan 23, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
265 commits
Select commit Hold shift + click to select a range
e76f932
app-containers/docker-buildx: Sync with Gentoo
Jan 13, 2025
e8ddc5f
app-containers/docker-cli: Sync with Gentoo
Jan 13, 2025
838f612
app-containers/netavark: Sync with Gentoo
Jan 13, 2025
18c4485
app-containers/podman: Sync with Gentoo
Jan 13, 2025
1dd6311
app-containers/runc: Sync with Gentoo
Jan 13, 2025
aa52710
app-crypt/gnupg: Sync with Gentoo
Jan 13, 2025
88b8987
app-crypt/gpgme: Sync with Gentoo
Jan 13, 2025
6401e9f
app-crypt/libb2: Sync with Gentoo
Jan 13, 2025
bd13fc4
app-crypt/mhash: Sync with Gentoo
Jan 13, 2025
f825a07
app-crypt/tpm2-tss: Sync with Gentoo
Jan 13, 2025
618969b
app-doc/eclass-manpages: Sync with Gentoo
Jan 13, 2025
b0f52e0
app-editors/nano: Sync with Gentoo
Jan 13, 2025
58d42b4
app-editors/vim: Sync with Gentoo
Jan 13, 2025
1651109
app-editors/vim-core: Sync with Gentoo
Jan 13, 2025
095fd36
app-emulation/qemu: Sync with Gentoo
Jan 13, 2025
ce60bb4
app-emulation/qemu-guest-agent: Sync with Gentoo
Jan 13, 2025
a3b7cad
app-emulation/virt-firmware: Sync with Gentoo
Jan 13, 2025
836c153
app-misc/jq: Sync with Gentoo
Jan 13, 2025
7915aa9
app-misc/pax-utils: Sync with Gentoo
Jan 13, 2025
e0874b1
app-portage/elt-patches: Sync with Gentoo
Jan 13, 2025
3b4a500
app-portage/getuto: Sync with Gentoo
Jan 13, 2025
4afe65e
app-portage/portage-utils: Sync with Gentoo
Jan 13, 2025
44323fc
app-shells/bash: Sync with Gentoo
Jan 13, 2025
a452bab
app-shells/bash-completion: Sync with Gentoo
Jan 13, 2025
28782c3
app-text/asciidoc: Sync with Gentoo
Jan 13, 2025
c4fc029
dev-build/cmake: Sync with Gentoo
Jan 13, 2025
8b8de32
dev-build/libtool: Sync with Gentoo
Jan 13, 2025
2f03a2e
dev-build/make: Sync with Gentoo
Jan 13, 2025
f3117e8
dev-build/meson: Sync with Gentoo
Jan 13, 2025
69178dc
dev-build/ninja: Sync with Gentoo
Jan 13, 2025
2c1a07e
dev-cpp/abseil-cpp: Sync with Gentoo
Jan 13, 2025
8b4f6f1
dev-cpp/glog: Sync with Gentoo
Jan 13, 2025
cea6c5e
dev-db/sqlite: Sync with Gentoo
Jan 13, 2025
6eb7698
dev-debug/gdb: Sync with Gentoo
Jan 13, 2025
e5b900a
dev-debug/strace: Sync with Gentoo
Jan 13, 2025
3e90128
dev-lang/perl: Sync with Gentoo
Jan 13, 2025
9e931c9
dev-lang/python: Sync with Gentoo
Jan 13, 2025
1f7be41
dev-lang/rust: Sync with Gentoo
Jan 13, 2025
d1282cf
dev-lang/rust-bin: Sync with Gentoo
Jan 13, 2025
e666628
dev-lang/rust-common: Sync with Gentoo
Jan 13, 2025
6a7f8e5
dev-lang/yasm: Sync with Gentoo
Jan 13, 2025
0dede30
dev-libs/cyrus-sasl: Sync with Gentoo
Jan 13, 2025
4e7d683
dev-libs/elfutils: Sync with Gentoo
Jan 13, 2025
bdc4297
dev-libs/expat: Sync with Gentoo
Jan 13, 2025
439e0dd
dev-libs/glib: Sync with Gentoo
Jan 13, 2025
0e5df33
dev-libs/gmp: Sync with Gentoo
Jan 13, 2025
028a7dd
dev-libs/gobject-introspection: Sync with Gentoo
Jan 13, 2025
4186600
dev-libs/gobject-introspection-common: Sync with Gentoo
Jan 13, 2025
9590093
dev-libs/jsoncpp: Sync with Gentoo
Jan 13, 2025
e99d8ee
dev-libs/libevent: Sync with Gentoo
Jan 13, 2025
7f1c72d
dev-libs/libgcrypt: Sync with Gentoo
Jan 13, 2025
69b3422
dev-libs/libgpg-error: Sync with Gentoo
Jan 13, 2025
3ef29ba
dev-libs/libltdl: Sync with Gentoo
Jan 13, 2025
913e1f2
dev-libs/libmspack: Sync with Gentoo
Jan 13, 2025
fee3c6c
dev-libs/libnl: Sync with Gentoo
Jan 13, 2025
17569db
dev-libs/libpwquality: Sync with Gentoo
Jan 13, 2025
a3c7861
dev-libs/libunistring: Sync with Gentoo
Jan 13, 2025
ea8620a
dev-libs/libuv: Sync with Gentoo
Jan 13, 2025
9edcdc0
dev-libs/libxml2: Sync with Gentoo
Jan 13, 2025
4a4e574
dev-libs/libxslt: Sync with Gentoo
Jan 13, 2025
84ef23f
dev-libs/nettle: Sync with Gentoo
Jan 13, 2025
139c45e
dev-libs/npth: Sync with Gentoo
Jan 13, 2025
7568e62
dev-libs/nspr: Sync with Gentoo
Jan 13, 2025
52efd85
dev-libs/oniguruma: Sync with Gentoo
Jan 13, 2025
3330970
dev-libs/opensc: Sync with Gentoo
Jan 13, 2025
74ba84d
dev-libs/protobuf: Sync with Gentoo
Jan 13, 2025
f092279
dev-libs/tree-sitter: Sync with Gentoo
Jan 13, 2025
d22b5dd
dev-libs/userspace-rcu: Sync with Gentoo
Jan 13, 2025
abc722a
dev-libs/xmlsec: Sync with Gentoo
Jan 13, 2025
d6a4943
dev-python/cachecontrol: Sync with Gentoo
Jan 13, 2025
b9b37e9
dev-python/charset-normalizer: Sync with Gentoo
Jan 13, 2025
533113a
dev-python/cryptography: Sync with Gentoo
Jan 13, 2025
5aa898a
dev-python/distro: Sync with Gentoo
Jan 13, 2025
6fb8483
dev-python/ensurepip-pip: Sync with Gentoo
Jan 13, 2025
13d71b8
dev-python/ensurepip-setuptools: Sync with Gentoo
Jan 13, 2025
1b61e37
dev-python/fastjsonschema: Sync with Gentoo
Jan 13, 2025
86a3430
dev-python/hatchling: Sync with Gentoo
Jan 13, 2025
54c4817
dev-python/jinja2: Sync with Gentoo
Jan 13, 2025
974e843
dev-python/msgpack: Sync with Gentoo
Jan 13, 2025
024304f
dev-python/pillow: Sync with Gentoo
Jan 13, 2025
2b8d5a2
dev-python/pip: Sync with Gentoo
Jan 13, 2025
ebbeb2d
dev-python/poetry-core: Sync with Gentoo
Jan 13, 2025
e4f5542
dev-python/pydecomp: Sync with Gentoo
Jan 13, 2025
1603fdd
dev-python/pygments: Sync with Gentoo
Jan 13, 2025
e3e8898
dev-python/resolvelib: Sync with Gentoo
Jan 13, 2025
666da0f
dev-python/rich: Sync with Gentoo
Jan 13, 2025
a452b78
dev-python/setuptools: Sync with Gentoo
Jan 13, 2025
3700c40
dev-python/six: Sync with Gentoo
Jan 13, 2025
dfc3477
dev-python/snakeoil: Sync with Gentoo
Jan 13, 2025
6264203
dev-python/tomli: Sync with Gentoo
Jan 13, 2025
f267d71
dev-python/trove-classifiers: Sync with Gentoo
Jan 13, 2025
154be82
dev-python/truststore: Sync with Gentoo
Jan 13, 2025
88aa88f
dev-python/urllib3: Sync with Gentoo
Jan 13, 2025
c14bbd1
dev-python/wheel: Sync with Gentoo
Jan 13, 2025
467332b
dev-util/bpftool: Sync with Gentoo
Jan 13, 2025
fcf94d8
dev-util/catalyst: Sync with Gentoo
Jan 13, 2025
ab348b6
dev-util/gdbus-codegen: Sync with Gentoo
Jan 13, 2025
f34d512
dev-util/glib-utils: Sync with Gentoo
Jan 13, 2025
750af8b
dev-util/gperf: Sync with Gentoo
Jan 13, 2025
22bf7a0
dev-util/maturin: Sync with Gentoo
Jan 13, 2025
4fc6400
dev-util/pahole: Sync with Gentoo
Jan 13, 2025
2e5fb13
dev-util/patchelf: Sync with Gentoo
Jan 13, 2025
581ef61
dev-util/perf: Sync with Gentoo
Jan 13, 2025
d72a198
dev-util/pkgcheck: Sync with Gentoo
Jan 13, 2025
c12ce1b
dev-util/pkgconf: Sync with Gentoo
Jan 13, 2025
1905665
dev-vcs/git: Sync with Gentoo
Jan 13, 2025
d16d997
eclass/cargo: Sync with Gentoo
Jan 13, 2025
feb8652
eclass/dist-kernel-utils: Sync with Gentoo
Jan 13, 2025
be50183
eclass/distutils-r1: Sync with Gentoo
Jan 13, 2025
28adc27
eclass/elisp-common: Sync with Gentoo
Jan 13, 2025
ea9794c
eclass/guile-utils: Sync with Gentoo
Jan 13, 2025
d2cdf69
eclass/java-utils-2: Sync with Gentoo
Jan 13, 2025
02c582e
eclass/linux-mod-r1: Sync with Gentoo
Jan 13, 2025
ea4a659
eclass/llvm-r1: Sync with Gentoo
Jan 13, 2025
6bb0a25
eclass/llvm-utils: Sync with Gentoo
Jan 13, 2025
4fe74bd
eclass/llvm: Sync with Gentoo
Jan 13, 2025
9b7a373
eclass/mono-env: Sync with Gentoo
Jan 13, 2025
d02447b
eclass/mount-boot-utils: Sync with Gentoo
Jan 13, 2025
59856cf
eclass/python-any-r1: Sync with Gentoo
Jan 13, 2025
4a88303
eclass/python-utils-r1: Sync with Gentoo
Jan 13, 2025
4d814b9
eclass/ruby-utils: Sync with Gentoo
Jan 13, 2025
63e7599
eclass/rust: Sync with Gentoo
Jan 13, 2025
3fbaa5a
eclass/secureboot: Sync with Gentoo
Jan 13, 2025
ea58932
eclass/toolchain-funcs: Sync with Gentoo
Jan 13, 2025
73253d7
eclass/toolchain: Sync with Gentoo
Jan 13, 2025
467f949
eclass/verify-sig: Sync with Gentoo
Jan 13, 2025
0c52d2b
eclass/xorg-3: Sync with Gentoo
Jan 13, 2025
2cacbea
licenses: Sync with Gentoo
Jan 13, 2025
73f2b8a
net-analyzer/openbsd-netcat: Sync with Gentoo
Jan 13, 2025
1bc902b
net-analyzer/tcpdump: Sync with Gentoo
Jan 13, 2025
a5d7ece
net-dialup/lrzsz: Sync with Gentoo
Jan 13, 2025
24f9c8f
net-dns/c-ares: Sync with Gentoo
Jan 13, 2025
1f4145b
net-dns/dnsmasq: Sync with Gentoo
Jan 13, 2025
4f03cea
net-firewall/ipset: Sync with Gentoo
Jan 13, 2025
19671a4
net-fs/cifs-utils: Sync with Gentoo
Jan 13, 2025
28e0c5d
net-libs/gnutls: Sync with Gentoo
Jan 13, 2025
e2bde6b
net-libs/libpcap: Sync with Gentoo
Jan 13, 2025
7fa0144
net-libs/nghttp2: Sync with Gentoo
Jan 13, 2025
acbbc31
net-misc/chrony: Sync with Gentoo
Jan 13, 2025
5375e02
net-misc/curl: Sync with Gentoo
Jan 13, 2025
fe12b11
net-misc/iperf: Sync with Gentoo
Jan 13, 2025
7115653
net-misc/passt: Sync with Gentoo
Jan 13, 2025
1a86129
net-misc/rsync: Sync with Gentoo
Jan 13, 2025
787fe46
net-misc/socat: Sync with Gentoo
Jan 13, 2025
d1c74fa
net-misc/wget: Sync with Gentoo
Jan 13, 2025
9292afb
net-nds/openldap: Sync with Gentoo
Jan 13, 2025
b621b4a
perl-core/File-Temp: Sync with Gentoo
Jan 13, 2025
73fdd95
profiles: Sync with Gentoo
Jan 13, 2025
42d5921
sys-apps/bubblewrap: Sync with Gentoo
Jan 13, 2025
df50ea9
sys-apps/checkpolicy: Sync with Gentoo
Jan 13, 2025
aa0e6ef
sys-apps/coreutils: Sync with Gentoo
Jan 13, 2025
43cee31
sys-apps/ethtool: Sync with Gentoo
Jan 13, 2025
90179de
sys-apps/file: Sync with Gentoo
Jan 13, 2025
263029e
sys-apps/findutils: Sync with Gentoo
Jan 13, 2025
4c06c2e
sys-apps/gawk: Sync with Gentoo
Jan 13, 2025
c700e57
sys-apps/hwdata: Sync with Gentoo
Jan 13, 2025
334353c
sys-apps/iproute2: Sync with Gentoo
Jan 13, 2025
0704798
sys-apps/kbd: Sync with Gentoo
Jan 13, 2025
ff28b78
sys-apps/kexec-tools: Sync with Gentoo
Jan 13, 2025
2d7a60d
sys-apps/less: Sync with Gentoo
Jan 13, 2025
62809de
sys-apps/nvme-cli: Sync with Gentoo
Jan 13, 2025
d21161c
sys-apps/pciutils: Sync with Gentoo
Jan 13, 2025
6bde08a
sys-apps/pcsc-lite: Sync with Gentoo
Jan 13, 2025
e0edf0e
sys-apps/portage: Sync with Gentoo
Jan 13, 2025
318c2ec
sys-apps/pv: Sync with Gentoo
Jan 13, 2025
d0167f9
sys-apps/sandbox: Sync with Gentoo
Jan 13, 2025
9b96e6c
sys-apps/texinfo: Sync with Gentoo
Jan 13, 2025
24dc33f
sys-apps/usbutils: Sync with Gentoo
Jan 13, 2025
a6c1c88
sys-apps/util-linux: Sync with Gentoo
Jan 13, 2025
e367c01
sys-apps/zram-generator: Sync with Gentoo
Jan 13, 2025
4218f74
sys-auth/sssd: Sync with Gentoo
Jan 13, 2025
bcfe0f5
sys-block/parted: Sync with Gentoo
Jan 13, 2025
79dd5ca
sys-block/thin-provisioning-tools: Sync with Gentoo
Jan 13, 2025
19c6951
sys-boot/gnu-efi: Sync with Gentoo
Jan 13, 2025
981f3fd
sys-devel/bc: Sync with Gentoo
Jan 13, 2025
8df8db9
sys-devel/binutils: Sync with Gentoo
Jan 13, 2025
eacff8f
sys-devel/binutils-config: Sync with Gentoo
Jan 13, 2025
871f12e
sys-devel/bison: Sync with Gentoo
Jan 13, 2025
5f89ee0
sys-devel/crossdev: Sync with Gentoo
Jan 13, 2025
0c6e2aa
sys-devel/gcc: Sync with Gentoo
Jan 13, 2025
d575e0c
sys-devel/gcc-config: Sync with Gentoo
Jan 13, 2025
bb2af3d
sys-devel/gettext: Sync with Gentoo
Jan 13, 2025
1696317
sys-devel/m4: Sync with Gentoo
Jan 13, 2025
eb46514
sys-firmware/edk2-bin: Sync with Gentoo
Jan 13, 2025
be61b0f
sys-firmware/intel-microcode: Sync with Gentoo
Jan 13, 2025
578e839
sys-firmware/ipxe: Sync with Gentoo
Jan 13, 2025
e4adb84
sys-firmware/seabios-bin: Sync with Gentoo
Jan 13, 2025
6e6c7f7
sys-fs/btrfs-progs: Sync with Gentoo
Jan 13, 2025
7702fdd
sys-fs/cryptsetup: Sync with Gentoo
Jan 13, 2025
0668485
sys-fs/e2fsprogs: Sync with Gentoo
Jan 13, 2025
bef0bc8
sys-fs/fuse-overlayfs: Sync with Gentoo
Jan 13, 2025
c5decfe
sys-fs/mtools: Sync with Gentoo
Jan 13, 2025
8fd669f
sys-fs/quota: Sync with Gentoo
Jan 13, 2025
9a3b9f4
sys-fs/udisks: Sync with Gentoo
Jan 13, 2025
8a9f0cb
sys-fs/xfsprogs: Sync with Gentoo
Jan 13, 2025
28df295
sys-fs/zfs: Sync with Gentoo
Jan 13, 2025
0990360
sys-fs/zfs-kmod: Sync with Gentoo
Jan 13, 2025
5f1adb3
sys-kernel/linux-headers: Sync with Gentoo
Jan 13, 2025
ff7460a
sys-libs/binutils-libs: Sync with Gentoo
Jan 13, 2025
d98bbf5
sys-libs/cracklib: Sync with Gentoo
Jan 13, 2025
5dad814
sys-libs/gdbm: Sync with Gentoo
Jan 13, 2025
03fdf01
sys-libs/ldb: Sync with Gentoo
Jan 13, 2025
0ee8ecb
sys-libs/libcap: Sync with Gentoo
Jan 13, 2025
c89ce06
sys-libs/libnvme: Sync with Gentoo
Jan 13, 2025
36e0de7
sys-libs/libselinux: Sync with Gentoo
Jan 13, 2025
27e8857
sys-libs/libunwind: Sync with Gentoo
Jan 13, 2025
5fcfbe4
sys-libs/liburing: Sync with Gentoo
Jan 13, 2025
6d6c7ef
sys-libs/ncurses: Sync with Gentoo
Jan 13, 2025
792a32d
sys-libs/readline: Sync with Gentoo
Jan 13, 2025
b29c092
sys-process/audit: Sync with Gentoo
Jan 13, 2025
44f08e9
sys-process/lsof: Sync with Gentoo
Jan 13, 2025
79128b4
sys-process/procps: Sync with Gentoo
Jan 13, 2025
659b34e
virtual/perl-Data-Dumper: Sync with Gentoo
Jan 13, 2025
07dae7f
virtual/perl-Encode: Sync with Gentoo
Jan 13, 2025
69e7657
virtual/perl-Exporter: Sync with Gentoo
Jan 13, 2025
47c8e14
virtual/perl-File-Spec: Sync with Gentoo
Jan 13, 2025
aa7fb6a
virtual/perl-Getopt-Long: Sync with Gentoo
Jan 13, 2025
c937f84
virtual/perl-IO: Sync with Gentoo
Jan 13, 2025
429dc8d
virtual/service-manager: Sync with Gentoo
Jan 13, 2025
9356e6a
x11-libs/pixman: Sync with Gentoo
Jan 13, 2025
2c05938
x11-misc/makedepend: Sync with Gentoo
Jan 13, 2025
bba5590
dev-python/jaraco-collections: new package required by setuptools
tormath1 Jan 3, 2025
c264d38
eclass/eapi9-pipestatus: Sync with Gentoo
krnowak Jan 13, 2025
5027199
overlay profiles: Mask >=sys-block/thin-provisioning-tools-1.0.14
krnowak Jan 13, 2025
b952004
overlay profiles: Mask >=sys-auth/sssd-2.9.6
krnowak Jan 14, 2025
060f7de
overlay profiles: Hack dev-util/bpftool into disabling co-re
krnowak Jan 14, 2025
63cc123
overlay profiles: Fix dev-libs/glib upgrade
krnowak Jan 14, 2025
2d12b18
perl-core/Getopt-Long: Add from Gentoo
krnowak Jan 14, 2025
850d602
overlay profiles: Add/update accept keywords
krnowak Jan 14, 2025
3401949
overlay profiles: Drop accept keywords for app-containers/aardvark-dns
krnowak Jan 14, 2025
4b00f88
overlay profiles: Drop accept keywords for app-containers/containers-…
krnowak Jan 14, 2025
e30221d
github: Add new packages to automation
krnowak Jan 14, 2025
d9bc309
overlay profiles: Drop accept keywords for app-containers/containers-…
krnowak Jan 14, 2025
5f81506
overlay profiles: Drop accept keywords for app-containers/containers-…
krnowak Jan 14, 2025
4f56225
overlay profiles: Drop accept keywords for app-containers/crun
krnowak Jan 14, 2025
f30ab49
overlay profiles: Drop accept keywords for app-containers/netavark
krnowak Jan 14, 2025
1707cd5
overlay profiles: Update accept keywords for app-emulation/virt-firmware
krnowak Jan 14, 2025
ee45f58
overlay profiles: Add accept keywords for net-misc/curl
krnowak Jan 16, 2025
13d823e
overlay profiles: Drop accept keywords for net-misc/passt
krnowak Jan 16, 2025
db39021
overlay profiles: Drop accept keywords for sys-apps/kexec-tools
krnowak Jan 16, 2025
8184136
overlay profiles: Drop accept keywords for sys-apps/util-linux
krnowak Jan 16, 2025
ee99288
overlay profiles: Drop accept keywords for sys-devel/binutils-config
krnowak Jan 16, 2025
c13d683
overlay profiles: Updated accept keywords for sys-firmware/edk2-bin
krnowak Jan 16, 2025
e83dfd4
overlay profiles: Drop accept keywords for sys-fs/fuse-overlayfs
krnowak Jan 16, 2025
6105582
overlay coreos-devel/sdk-depends: Pull common introspection package i…
krnowak Jan 17, 2025
e9f0cb3
overlay profiles: Clean up introspection handling
krnowak Jan 17, 2025
8ffb6f8
dev-libs/gobject-introspection: Drop the troublesome package
krnowak Jan 17, 2025
ced2b4f
.github: Drop dev-libs/gobject-introspection from automation
krnowak Jan 17, 2025
7d653ce
changelog: Add entries
krnowak Jan 22, 2025
adc5aee
overlay coreos/config: Mask some binaries
krnowak Jan 22, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 3 additions & 1 deletion .github/workflows/portage-stable-packages-list
Original file line number Diff line number Diff line change
Expand Up @@ -229,7 +229,6 @@ dev-libs/elfutils
dev-libs/expat
dev-libs/glib
dev-libs/gmp
dev-libs/gobject-introspection
dev-libs/gobject-introspection-common
dev-libs/inih
dev-libs/jansson
Expand Down Expand Up @@ -314,6 +313,7 @@ dev-python/hatchling
dev-python/hatch-vcs
dev-python/idna
dev-python/installer
dev-python/jaraco-collections
dev-python/jaraco-context
dev-python/jaraco-functools
dev-python/jaraco-text
Expand Down Expand Up @@ -395,6 +395,7 @@ eclass/desktop.eclass
eclass/dist-kernel-utils.eclass
eclass/distutils-r1.eclass
eclass/eapi8-dosym.eclass
eclass/eapi9-pipestatus.eclass
eclass/edo.eclass
eclass/edos2unix.eclass
eclass/elisp-common.eclass
Expand Down Expand Up @@ -548,6 +549,7 @@ net-nds/rpcbind
net-vpn/wireguard-tools

perl-core/File-Temp
perl-core/Getopt-Long

profiles

Expand Down
2 changes: 2 additions & 0 deletions changelog/security/2025-01-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
- containers-storage, podman ([CVE-2024-9676](https://nvd.nist.gov/vuln/detail/CVE-2024-9676))
- curl ([CVE-2024-11053](https://nvd.nist.gov/vuln/detail/CVE-2024-11053), [CVE-2024-9681](https://nvd.nist.gov/vuln/detail/CVE-2024-9681))
38 changes: 38 additions & 0 deletions changelog/updates/2025-01-22-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
- SDK: qemu ([8.2.7](https://lists.gnu.org/archive/html/qemu-devel/2024-09/msg03900.html))
- azure, dev, gce, sysext-python: python ([3.11.11_p1](https://www.python.org/downloads/release/python-31111/))
- base, dev: audit ([4.0.2](https://github.com/linux-audit/audit-userspace/releases/tag/v4.0.2))
- base, dev: bpftool ([7.5.0](https://github.com/libbpf/bpftool/releases/tag/v7.5.0))
- base, dev: btrfs-progs ([6.12](https://raw.githubusercontent.com/kdave/btrfs-progs/refs/tags/v6.12/CHANGES))
- base, dev: c-ares ([1.34.3](https://github.com/c-ares/c-ares/releases/tag/v1.34.3) (includes [1.34.2](https://github.com/c-ares/c-ares/releases/tag/v1.34.2), [1.34.1](https://github.com/c-ares/c-ares/releases/tag/v1.34.1), [1.34.0](https://github.com/c-ares/c-ares/releases/tag/v1.34.0)))
- base, dev: ethtool ([6.10](https://git.kernel.org/pub/scm/network/ethtool/ethtool.git/tree/NEWS?h=v6.10))
- base, dev: glib ([2.80.5](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.5) (includes [2.80.4](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.4), [2.80.3](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.3), [2.80.2](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.2), [2.80.1](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.1), [2.80.0](https://gitlab.gnome.org/GNOME/glib/-/releases/2.80.0)))
- base, dev: gnupg ([2.4.6](https://lists.gnupg.org/pipermail/gnupg-announce/2024q4/000486.html))
- base, dev: hwdata ([0.390](https://github.com/vcrhonek/hwdata/releases/tag/v0.390))
- base, dev: intel-microcode ([20241112](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20241112) (includes [20241029](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20241029)))
- base, dev: iproute2 ([6.12.0](https://lore.kernel.org/netdev/[email protected]/))
- base, dev: kexec-tools ([2.0.30](https://github.com/horms/kexec-tools/commits/v2.0.30/))
- base, dev: libcap ([2.71](https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.oq9dsdhihxp5))
- base, dev: libgpg-error ([1.51](https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgpg-error.git;a=blob;f=NEWS;h=75f2b2d220de4e4f53252d3367950ecb2ab85079;hb=b0bb9266010d84b30fa2dc6a2127b7e40dc03660))
- base, dev: libnvme ([1.11.1](https://github.com/linux-nvme/libnvme/releases/tag/v1.11.1) (includes [1.11](https://github.com/linux-nvme/libnvme/releases/tag/v1.11)))
- base, dev: libxml2 ([2.12.9](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.9))
- base, dev: lsof ([4.99.4](https://github.com/lsof-org/lsof/releases/tag/4.99.4))
- base, dev: npth ([1.8](https://git.gnupg.org/cgi-bin/gitweb.cgi?p=npth.git;a=blob;f=NEWS;h=0f8d78958d8059de95e363a977051995e05dc691;hb=64905e765aad9de6054ef70a97fc30bd992ce999))
- base, dev: nvme-cli ([2.11](https://github.com/linux-nvme/nvme-cli/releases/tag/v2.11))
- base, dev: openldap ([2.6.8](https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_6_8/CHANGES) (includes [2.6.7](https://git.openldap.org/openldap/openldap/-/blob/OPENLDAP_REL_ENG_2_6_7/CHANGES)))
- base, dev: strace ([6.12](https://github.com/strace/strace/releases/tag/v6.12) (includes [6.11](https://github.com/strace/strace/releases/tag/v6.11), [6.10](https://github.com/strace/strace/releases/tag/v6.10)))
- base, dev: usbutils ([018](https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usbutils.git/tree/NEWS?h=v018))
- base, dev: xfsprogs ([6.11.0](https://git.kernel.org/pub/scm/fs/xfs/xfsprogs-dev.git/tree/doc/CHANGES?h=v6.11.0))
- dev: bash-completion ([2.15.0](https://github.com/scop/bash-completion/releases/tag/2.15.0))
- dev: binutils ([2.43](https://lists.gnu.org/archive/html/info-gnu/2024-08/msg00001.html))
- docker: docker-buildx ([0.14.0](https://github.com/docker/buildx/releases/tag/v0.14.0) (includes [0.13.0](https://github.com/docker/buildx/releases/tag/v0.13.0), [0.12.0](https://github.com/docker/buildx/releases/tag/v0.12.0), [0.11.0](https://github.com/docker/buildx/releases/tag/v0.11.0)))
- gce: six ([1.17.0](https://github.com/benjaminp/six/blob/1.17.0/CHANGES))
- sysext-podman: containers-storage ([1.55.1](https://github.com/containers/storage/releases/tag/v1.55.1))
- sysext-podman: gpgme ([1.24.1](https://dev.gnupg.org/T7440) (includes [1.24.0](https://dev.gnupg.org/T7376)))
- sysext-podman: podman ([5.3.0](https://github.com/containers/podman/releases/tag/v5.3.0))
- sysext-python: charset-normalizer ([3.4.1](https://github.com/jawah/charset_normalizer/releases/tag/3.4.1))
- sysext-python: pip ([24.3.1](https://github.com/pypa/pip/blob/24.3.1/NEWS.rst) (includes [24.3](https://github.com/pypa/pip/blob/24.3/NEWS.rst))
- sysext-python: setuptools ([75.6.0](https://github.com/pypa/setuptools/blob/v75.6.0/NEWS.rst) (includes [75.5.0](https://github.com/pypa/setuptools/blob/75.5.0/NEWS.rst), [75.4.0](https://github.com/pypa/setuptools/blob/75.4.0/NEWS.rst), [75.3.0](https://github.com/pypa/setuptools/blob/75.3.0/NEWS.rst), [75.2.0](https://github.com/pypa/setuptools/blob/75.2.0/NEWS.rst), [75.1.1](https://github.com/pypa/setuptools/blob/75.1.1/NEWS.rst), [75.1.0](https://github.com/pypa/setuptools/blob/75.1.0/NEWS.rst), [75.0.0](https://github.com/pypa/setuptools/blob/75.0.0/NEWS.rst)))
- sysext-python: urllib3 ([2.3.0](https://github.com/urllib3/urllib3/releases/tag/2.3.0))
- sysext-python: wheel ([0.45.1](https://github.com/pypa/wheel/releases/tag/0.45.1) (includes [0.45.0](https://github.com/pypa/wheel/releases/tag/0.45.0)))
- sysext-zfs: zfs ([2.2.7](https://github.com/openzfs/zfs/releases/tag/zfs-2.2.7) (includes [2.2.6](https://github.com/openzfs/zfs/releases/tag/zfs-2.2.6)))
- vmware: libltdl ([2.5.4](https://savannah.gnu.org/news/?id=10693) (includes [2.5.3](https://savannah.gnu.org/news/?id=10676), [2.5.2](https://savannah.gnu.org/news/?id=10669), [2.5.1](https://savannah.gnu.org/news/?id=10660), [2.5.0](https://savannah.gnu.org/news/?id=10631)))
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ DEPEND="
app-text/mandoc
coreos-base/hard-host-depends
coreos-base/coreos-sb-keys
dev-libs/gobject-introspection
dev-libs/gobject-introspection-common
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this needs to be explicitly included here.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I did a grep for dev-libs/gobject-introspection-common and it seems to be pulled in by three packages:

  • dev-libs/glib - conditionally RDEPEND on USE=introspection, which we disable
  • sys-auth/polkit - BDEPEND, this package seems to be built only for board
  • sys-fs/udisks - BDEPEND, but we actually are not even building this package, so it should be dropped (not in this PR, though)

Seems like nothing would pull dev-libs/gobject-introspection-common through coreos-devel/sdk-depends if we removed the line from the ebuild. This would result in the package being built during board packages build instead of SDK build. Since (ideally) we want the SDK to provide all BDEPEND packages of board packages, this should stay.

dev-python/setuptools
dev-python/six
dev-util/catalyst
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Do not install gobject-introspection binaries in production images.
if [[ $(cros_target) != "cros_host" ]] ; then
glib_mask="/usr/bin/gi-* /usr/lib*/libgirepository-2.0*"
PKG_INSTALL_MASK+=" ${glib_mask}"
INSTALL_MASK+=" ${glib_mask}"
unset glib_mask
fi
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ USE_EXPAND="${USE_EXPAND} TESTS"
# For now this is only informational and set by coreos-go.eclass
USE_EXPAND="${USE_EXPAND} GO_VERSION"

USE="${USE} -cracklib -introspection -cups -tcpd -berkdb"
USE="${USE} -cracklib -cups -tcpd -berkdb"

# Use Python 3 as the default version
USE="${USE} -python_single_target_python2_7 python_single_target_python3_11"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,34 +7,16 @@
# Gentoo upstream package stabilisation
# (the following packages are "unstable" upstream; we're stabilising these)

# Needed by updated app-containers/containers-common
=app-containers/aardvark-dns-1.12.2-r1 ~amd64 ~arm64

# Handled by automation
=app-containers/containerd-1.7.23 ~amd64 ~arm64 # DO NOT EDIT THIS LINE. Added by containerd-apply-patch.sh on 2024-10-18 08:06:10

# Needed to address CVE-2024-9341.
=app-containers/containers-common-0.60.4 ~amd64 ~arm64

# Needed to address CVE-2024-3727.
=app-containers/containers-image-5.32.2 ~amd64 ~arm64

# Needed by updated app-containers/containers-common
=app-containers/containers-storage-1.55.0 ~amd64 ~arm64

# Keep versions on both arches in sync.
=app-containers/cri-tools-1.27.0 ~arm64

# Needed by updated app-containers/containers-common
=app-containers/crun-1.17 ~amd64 ~arm64

# Accept unstable for Docker and its CLI.
=app-containers/docker-27.3.1 ~amd64 ~arm64
=app-containers/docker-cli-27.3.1 ~amd64 ~arm64

# Needed by updated app-containers/containers-common
=app-containers/netavark-1.12.2-r1 ~amd64 ~arm64

# These seem to be the versions we initially got, but the
# modifications made to the ebuilds were clobbered, so these are here
# to keep using the same version. Can be dropped when these or newer
Expand All @@ -57,7 +39,7 @@
=app-crypt/p11-kit-0.25.5 ~amd64 ~arm64

# Needed in SDK for Secure Boot.
=app-emulation/virt-firmware-24.7 ~amd64 ~arm64
=app-emulation/virt-firmware-24.7 ~amd64

# Needed by arm64-native SDK.
=app-emulation/open-vmdk-1.0 *
Expand All @@ -81,7 +63,7 @@
=dev-libs/luksmeta-9-r1 **

# Keep versions on both arches in sync.
=dev-util/bpftool-7.4.0 ~arm64
=dev-util/bpftool-7.5.0 ~arm64

# Catalyst 4 is not stable yet, but earlier versions are masked now.
=dev-util/catalyst-4.0.0 ~amd64 ~arm64
Expand All @@ -91,30 +73,25 @@
=net-libs/libnetfilter_cthelper-1.0.1-r1 ~arm64
=net-libs/libnetfilter_cttimeout-1.0.1 ~arm64

# Needed by updated app-containers/containers-common
=net-misc/passt-2024.09.06 ~amd64 ~arm64
# Needed to address CVE-2024-11053 and CVE-2024-9681
=net-misc/curl-8.11.1-r2 ~amd64 ~arm64

# Keep versions on both arches in sync.
=net-nds/openldap-2.6.6-r2 ~amd64
=net-nds/openldap-2.6.8 ~amd64

# Package has not been stabilised yet.
=sys-apps/azure-vm-utils-0.4.0 ~amd64 ~arm64

# Keep versions on both arches in sync.
=sys-apps/kexec-tools-2.0.29-r1 ~arm64
=sys-apps/util-linux-2.40.2 ~arm64
=sys-apps/zram-generator-1.1.2-r1 ~arm64
=sys-auth/sssd-2.9.5 ~arm64
=sys-boot/mokutil-0.7.2 **

# Enable ipvsadm for arm64.
=sys-cluster/ipvsadm-1.31-r1 ~arm64

# Keep versions on both arches in sync.
=sys-devel/binutils-config-5.5.2 ~arm64

# Needed in SDK for Secure Boot on arm64. Also addresses CVE-2024-1298.
=sys-firmware/edk2-bin-202408 ~amd64 ~arm64
=sys-firmware/edk2-bin-202408 ~amd64

# Needed by updated app-containers/containers-common
=sys-fs/fuse-overlayfs-1.14 ~amd64 ~arm64
# Keep versions on both arches in sync.
=sys-process/audit-4.0.2-r1 ~arm64
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,9 @@

# Update engine needs updating to use a newer version of protobuf.
>=dev-libs/protobuf-22.0

# Pulls in LLVM and clang.
>=sys-block/thin-provisioning-tools-1.0.14

# Pulls in python into production.
>=sys-auth/sssd-2.9.6
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,7 @@ sys-fs/udev-init-scripts-35
# A dependency of dev-libs/libtracefs. It's apparently for docs, that
# we don't even include anywhere.
dev-util/source-highlight-3.1.9-r2

# Pulled in by bpftool[-clang], We never provided co-re in bpftool and
# for now continue to do so.
sys-devel/bpf-toolchain-14.2.0_p1
Original file line number Diff line number Diff line change
Expand Up @@ -112,9 +112,6 @@ net-firewall/iptables nftables
# Install `perl` with a minimal set of dependencies
dev-lang/perl minimal

# Remove support for GObject introspection
sys-auth/polkit -introspection

# enables ELF support to e.g. allow tc to handle BPF filters.
sys-apps/iproute2 elf

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,3 @@ sys-fs/btrfs-progs man
# put anywhere. Thus avoid pulling more dependencies than necessary
# for throw-away things.
dev-python/pillow jpeg

# bpftool ebuild started to bdepend on sys-devel/clang unconditionally
# in order to build co-re support. We can try avoiding it by masking
# the USE flag that currently gets enabled by default.
dev-util/bpftool llvm_slot_18
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,6 @@ python_single_target_python3_13
# We don't care about i10n, takes too much space, pulls in too many
# extra dependencies.
nls

# We don't care about GObject introspection.
introspection
Original file line number Diff line number Diff line change
Expand Up @@ -50,3 +50,10 @@ sys-fs/fuse -suid

# skip dependency for this sysext package
net-misc/chrony -readline

# Do not pull llvm into prod (use binutils-libs instead).
#
# Disable co-re (we never had it enabled, but now it's forced by the
# ebuild; this will pull sys-devel/bpf-toolchain, which we put into
# package.provided in SDK).
dev-util/bpftool -llvm -clang
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,6 @@ INSTALL_MASK="${INSTALL_MASK}
/usr/share/eselect
/usr/share/gdb
/usr/share/gettext
/usr/share/gobject-introspection-1.0
/usr/share/pkgconfig
/usr/share/readline
/usr/src
Expand Down

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Copyright 1999-2024 Gentoo Authors
# Copyright 1999-2025 Gentoo Authors
# Distributed under the terms of the GNU General Public License v2

# XXX: atm, libbz2.a is always PIC :(, so it is always built quickly
Expand Down Expand Up @@ -70,7 +70,8 @@ multilib_src_compile() {

multilib_src_test() {
cp "${S}"/sample* "${BUILD_DIR}" || die
bemake -f "${S}"/Makefile check
ln -s libbz2.so.1.0 libbz2.so.1 || die
LD_LIBRARY_PATH=".:${LD_LIBRARY_PATH}" bemake -f "${S}"/Makefile check
}

multilib_src_install() {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@

EAPI=8

inherit autotools flag-o-matic
inherit autotools flag-o-matic toolchain-funcs

DESCRIPTION="Parallel bzip2 utility"
HOMEPAGE="https://github.com/kjn/lbzip2/"
Expand All @@ -29,6 +29,10 @@ src_prepare() {
src_configure() {
use static && append-ldflags -static

# fix clang miscompilation: #910438
# see also: https://github.com/llvm/llvm-project/issues/87189
tc-is-clang && test-flag-CC -mno-avx512f && append-cflags -mno-avx512f

local myeconfargs=(
$(use_enable debug tracing)
)
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,2 @@
DIST libarchive-3.7.6.tar.xz 5458552 BLAKE2B 3251dc4d59867d1c9b43e78ac7735c27670e819a1aba4f4a76372b8509e2427ff24e379f6102a4cc3c92b965d182c8939bb6df4c82d4d1141cdd1db13bf039a2 SHA512 3ca90d665772418b9ac444044511989e81e785a13db3c101851390ba7c2ba0793c799cedb9df990e900ab78c98207f70ecee7e21829578555dde99424950ae2a
DIST libarchive-3.7.6.tar.xz.asc 659 BLAKE2B 9f6a621dd4aa20f06dff71225723e60a6cee1f2a54ff07d2d19670153105f2f75d6439320f49eb46c28a4416828af7dc4f0d827e46ec9aeb5b703f06eb329d77 SHA512 2840b13f910f47d34daeed9680beb4b3cdde2d7de26ab8453756261c51fb7a39b727454f370b0ee60f8e1646c65544331a22558cbe8faf79a201b1d1346b37c1
DIST libarchive-3.7.7.tar.xz 5480580 BLAKE2B e118c693f7a78e86ab868fc6c2c77beba539cf5c7d5999e270cdceb225e9f85c68c938ec6ce3a33f75b2a44a6f7debe2c280d2573c1bcf05806300e8dce1a4f0 SHA512 2524f71f4c2ebc254a1927279be3394e820d0a0c6dec7ef835a862aa08c35756edaa4208bcdc710dd092872b59c200b555b78670372e2830822e278ff1ec4e4a
DIST libarchive-3.7.7.tar.xz.asc 659 BLAKE2B 066d97312ded566e2c96ffc4603477fc829bcf17dcc057249dad51a0abea7aa5559691c0c25b581212168f8442db028a2dcc34148c648e973450fcb9dd5e35af SHA512 9f532df76bc381b40d7454a7bbbab85e34a646167ee7ca197fae45c713002e32f40e2b2871bc4a0d7149df19e69e2079efd9ab2f22eccf959b203604293d6094
Loading