877 Commits

Author SHA1 Message Date
Christian Breunig
fd737172f1 T861: add UEFI Secure Boot support
This adds support for UEFI Secure Boot. It adds the missing pieces to the Linux
Kernel and enforces module signing. This results in an additional security
layer where untrusted (unsigned) Kernel modules can no longer be loaded into
the live system.

NOTE: This commit will not work unless signing keys are present. Arbitrary
keys can be generated using instructions found in:

  data/live-build-config/includes.chroot/var/lib/shim-signed/mok/README.md
2024-09-14 23:05:23 +02:00
Christian Breunig
f523ae5cac Kernel: T5887: update Linux Kernel to v6.6.51 2024-09-14 20:58:44 +02:00
Christian Breunig
fd7d1d0d20 Kernel: T861: remove superfluous architecture from Kernel string 2024-09-07 21:31:46 +02:00
Christian Breunig
68671774f9 T4974: remove package openvpn-dco as it has a proper dependency via vyos-1x 2024-09-05 07:14:43 +02:00
Christian Breunig
f53921911e telegraf: T3664: remove package dependency
Telegraf is not a full VyOS feature with a proper dependency in place via
vyos-1x package. Drop this temporary dependency.
2024-09-05 07:13:08 +02:00
Christian Breunig
d50707bb29 T1416: remove deprecated default-union-grub-entry 2024-09-05 07:13:08 +02:00
Christian Breunig
c635fc980e
Kernel: T5887: update Linux Kernel to v6.6.49 2024-09-04 21:23:47 +02:00
Christian Breunig
c5c6a1347c
Merge pull request #738 from bk2zsto/image_format_singular
build: T6666: singular image_format in flavor files
2024-08-22 11:47:04 +02:00
bk2zsto
16a4c4d503 build: T6666: singular image_format in flavor files 2024-08-20 09:49:04 -04:00
Christian Breunig
035cf9bc12
Kernel: T5887: update Linux Kernel to v6.6.47 2024-08-20 07:10:48 +02:00
Christian Breunig
faa6453ec8 Kernel: T5887: update Linux Kernel to v6.6.45 2024-08-11 14:46:58 +02:00
Christian Breunig
afbe969377 Kernel: T5887: update Linux Kernel to v6.6.43 2024-07-29 08:04:13 +02:00
Christian Breunig
58025b253c build: T6231: include out-of-tree Mellanox driver in image 2024-07-25 20:31:30 +02:00
Christian Breunig
11e1620683
Kernel: T5887: update Linux Kernel to v6.6.42 2024-07-25 15:50:51 +02:00
Christian Breunig
c3513444a9
Merge pull request #709 from c-po/podman-T6598
podman: T6598: add custom podman build for version 4.9.5
2024-07-24 20:06:39 +02:00
Christian Breunig
a9baaaba16 podman: T6598: add custom podman build for version 4.9.5 2024-07-23 08:03:07 +02:00
Christian Breunig
12e531194d Kernel: T5887: update Linux Kernel to v6.6.41 2024-07-20 09:36:01 +02:00
Christian Breunig
303ba89c14 Kernel: T5887: update Linux Kernel to v6.6.40 2024-07-17 08:47:27 +02:00
Christian Breunig
022bb44588 Kernel: T5887: update Linux Kernel to v6.6.39 2024-07-12 14:47:09 +02:00
Christian Breunig
16753c9d3a
Merge pull request #690 from c-po/podman
container: T5867: pin specific podman version
2024-07-08 17:00:22 +02:00
Christian Breunig
0094dc2ecc container: T5867: pin specific podman version
As of Debian version 4.9.5+ds1-1 podman increased the dependency on
libc6 and libgpgme11t64.

  podman : Depends: libc6 (>= 2.38) but 2.36-9+deb12u7 is to be installed
           Depends: libgpgme11t64 (>= 1.4.1) but it is not going to be installed

Pin the version to a prior one that requires the old libc.
2024-07-08 10:13:08 +02:00
Christian Breunig
2e6e43ee71
Kernel: T5887: update Linux Kernel to v6.6.37 2024-07-06 09:45:52 +02:00
Christian Breunig
dd322145be Kernel: T5887: update Linux Kernel to v6.6.36 2024-07-02 21:46:01 +02:00
Christian Breunig
ff75b07681 T6527: remove legacy packages 2024-06-30 07:33:00 +02:00
Christian Breunig
057db80447
Merge pull request #667 from c-po/T6507-drop-vyos-world
T6507: remove references to vyos-world package
2024-06-27 16:44:28 +02:00
Christian Breunig
6e0f62a0ca T6507: remove references to vyos-world package
As we got rid of most of the old vyatta packages we can now also discontinue
vyos-world. It only served the purpose of keeping the package list during ISO
build small.
2024-06-22 09:07:05 +02:00
Christian Breunig
0c8ffe63e1 Kernel: T5887: update Linux Kernel to v6.6.35 2024-06-22 08:21:07 +02:00
Christian Breunig
41771586bd Kernel: T5887: update Linux Kernel to v6.6.34 2024-06-17 20:07:32 +02:00
Christian Breunig
2b3d116785
Merge pull request #653 from ZenithTecnologia/current
docker: arm: T6474: Initial support for dynamic arch toml loading
2024-06-15 22:32:13 +02:00
Christian Breunig
f2154b4252
Kernel: T5887: update Linux Kernel to v6.6.33 2024-06-12 21:09:26 +02:00
Leonardo Amaral
c0af57d68c
docker: arm: T6474: Added Salt Project repo for armhf
Signed-off-by: Leonardo Amaral <contato@leonardoamaral.com.br>
2024-06-11 18:04:01 -03:00
John Estabrook
3f42cf0865 migration: T6006: move config.boot.default to vyos-1x 2024-06-05 20:00:59 -05:00
Daniil Baturin
5753b4b624 build: T6414: rename the "iso" flavor to "generic" 2024-05-28 19:33:29 +01:00
Christian Breunig
f3cde18f6f Kernel: T5887: update Linux Kernel to v6.6.32 2024-05-25 17:16:45 +02:00
Christian Breunig
d1852e392e
Merge pull request #629 from c-po/T5887-kernel
Kernel: T5887: update Linux Kernel to v6.6.31
2024-05-19 08:22:04 +02:00
Christian Breunig
20b42272c5 Kernel: T5887: update Linux Kernel to v6.6.31 2024-05-19 08:19:24 +02:00
John Estabrook
04948aa983 T6356: normalize '.., ntp, server' path syntax in config.boot.default 2024-05-16 13:19:02 -05:00
Christian Breunig
1f59787ff6
Merge pull request #624 from c-po/target
hooks: T6346: set default boot target to multi-user.target
2024-05-16 07:31:27 +02:00
Christian Breunig
ca31af2cc3 hooks: T6346: set default boot target to multi-user.target 2024-05-16 07:19:59 +02:00
Christian Breunig
a33e9cfe0b
Merge pull request #614 from aidan-gibson/current
T6333 non-free-firmware to trixie
2024-05-16 07:19:17 +02:00
Aidan Gibson
7f82191abe T6333: drop reference to non-free of trixie as it's not used 2024-05-16 07:18:33 +02:00
Christian Breunig
fabf5326b8
Merge pull request #582 from 0xThiebaut/suricata
suricata: T751: Disable suricata.service by default
2024-05-14 19:27:46 +02:00
Viacheslav Hletenko
618b1379b7 T3420: Remove service upnp 2024-05-14 16:59:59 +00:00
Christian Breunig
884de8dc76 container: T5867: podman depends on libgpgme11t64 from trixie 2024-05-03 14:13:35 +02:00
Maxime THIEBAUT
845846108e suricata: T751: Disable suricata.service by default 2024-05-03 00:31:38 +02:00
Christian Breunig
5978fd1df8 Kernel: T5887: update Linux Kernel to v6.6.30 2024-05-02 20:53:33 +02:00
Christian Breunig
471ac04b05
Kernel: T5887: update Linux Kernel to v6.6.29 2024-04-28 15:55:55 +02:00
Daniil Baturin
1edab4ef0b iso: T6262: update the boot splash for 1.5/Circinus
Picture courtesy of Oleg Gorobets
2024-04-23 11:31:22 +01:00
Christian Breunig
d9499a16a4
Kernel: T5887: update Linux Kernel to v6.6.28 2024-04-20 10:01:51 +02:00
Christian Breunig
eeb1a98a77
Kernel: T5887: update Linux Kernel to v6.6.27 2024-04-14 07:50:20 +02:00