840 Commits

Author SHA1 Message Date
Christian Breunig
f36d645550 T6844: use our own mirror of the salt repository 2024-11-01 09:36:16 +01:00
Viacheslav Hletenko
7cd109889b Kernel: T5887: Revert update Linux Kernel to v6.6.58
This reverts commit 6e256633b34dc737a812b0b8d253733608eb8ca8.

Issues with the kernel and netfilter IPv6
https://vyos.dev/T6814
https://bugzilla.redhat.com/show_bug.cgi?id=2321325
2024-10-25 12:21:47 +00:00
Christian Breunig
6e256633b3
Kernel: T5887: update Linux Kernel to v6.6.58 2024-10-22 20:24:28 +02:00
Daniil Baturin
bf2e6afc49 build: T6776: use the official Zabbix repo for zabbix-agent2 2024-10-17 11:13:35 +01:00
Christian Breunig
267bd9ca61 Kernel: T5887: update Linux Kernel to v6.6.56 2024-10-12 08:04:09 +02:00
Daniil Baturin
4d68265e7a build: T6231: remove Mellanox OFED drivers and tools
until their license status is confirmed
2024-10-10 09:51:34 +01:00
Daniil Baturin
49d41fa34a
Merge pull request #762 from sever-sever/T6713-current-realtek
T6713: Update Realtek r8152 driver
2024-10-07 15:58:30 +01:00
Christian Breunig
1e53e6451c Kernel: T5887: update Linux Kernel to v6.6.54 2024-10-05 08:15:55 +02:00
Viacheslav Hletenko
a3b515ca71 T6713: Update Realtek r8152 driver 2024-10-02 11:48:46 +00:00
Viacheslav Hletenko
7bd5496de1 T6755: Change default vyos mirror URL 2024-10-02 07:34:49 +00:00
Christian Breunig
d235b31a09 T861: sign all Kernel modules with an ephemeral key
The shim review board (which is the secure boot base loader) recommends using
ephemeral keys when signing the Linux Kernel. This commit enables the Kernel
build system to generate a one-time ephemeral key that is used to:

* sign all build-in Kernel modules
* sign all other out-of-tree Kernel modules

The key lives in /tmp and is destroyed after the build container exits and is
named: "VyOS build time autogenerated kernel key".

In addition the Kernel now uses CONFIG_MODULE_SIG_FORCE. This now makes it
unable to load any Kernel Module to the image that is NOT signed by the
ephemeral key.
2024-09-25 20:24:21 +02:00
Christian Breunig
88f072df3d Kernel: T5887: update Linux Kernel to v6.6.52 2024-09-22 09:31:31 +02:00
Christian Breunig
53bd06d17b T861: stripping Kernel modules would also remove module signatures
As the VyOS Linux Kernel will be compiled with CONFIG_MODULE_SIG_FORCE all
driver modules need to be cryptographically signed. This happens during build
of the Kernel and it's 3rd party modules.

Stripping the objects would remove said signature and the system will be unable
to boot b/c of CONFIG_MODULE_SIG_FORCE.
2024-09-22 09:31:31 +02:00
Christian Breunig
fd737172f1 T861: add UEFI Secure Boot support
This adds support for UEFI Secure Boot. It adds the missing pieces to the Linux
Kernel and enforces module signing. This results in an additional security
layer where untrusted (unsigned) Kernel modules can no longer be loaded into
the live system.

NOTE: This commit will not work unless signing keys are present. Arbitrary
keys can be generated using instructions found in:

  data/live-build-config/includes.chroot/var/lib/shim-signed/mok/README.md
2024-09-14 23:05:23 +02:00
Christian Breunig
f523ae5cac Kernel: T5887: update Linux Kernel to v6.6.51 2024-09-14 20:58:44 +02:00
Christian Breunig
fd7d1d0d20 Kernel: T861: remove superfluous architecture from Kernel string 2024-09-07 21:31:46 +02:00
Christian Breunig
68671774f9 T4974: remove package openvpn-dco as it has a proper dependency via vyos-1x 2024-09-05 07:14:43 +02:00
Christian Breunig
f53921911e telegraf: T3664: remove package dependency
Telegraf is not a full VyOS feature with a proper dependency in place via
vyos-1x package. Drop this temporary dependency.
2024-09-05 07:13:08 +02:00
Christian Breunig
d50707bb29 T1416: remove deprecated default-union-grub-entry 2024-09-05 07:13:08 +02:00
Christian Breunig
c635fc980e
Kernel: T5887: update Linux Kernel to v6.6.49 2024-09-04 21:23:47 +02:00
Christian Breunig
c5c6a1347c
Merge pull request #738 from bk2zsto/image_format_singular
build: T6666: singular image_format in flavor files
2024-08-22 11:47:04 +02:00
bk2zsto
16a4c4d503 build: T6666: singular image_format in flavor files 2024-08-20 09:49:04 -04:00
Christian Breunig
035cf9bc12
Kernel: T5887: update Linux Kernel to v6.6.47 2024-08-20 07:10:48 +02:00
Christian Breunig
faa6453ec8 Kernel: T5887: update Linux Kernel to v6.6.45 2024-08-11 14:46:58 +02:00
Christian Breunig
afbe969377 Kernel: T5887: update Linux Kernel to v6.6.43 2024-07-29 08:04:13 +02:00
Christian Breunig
58025b253c build: T6231: include out-of-tree Mellanox driver in image 2024-07-25 20:31:30 +02:00
Christian Breunig
11e1620683
Kernel: T5887: update Linux Kernel to v6.6.42 2024-07-25 15:50:51 +02:00
Christian Breunig
c3513444a9
Merge pull request #709 from c-po/podman-T6598
podman: T6598: add custom podman build for version 4.9.5
2024-07-24 20:06:39 +02:00
Christian Breunig
a9baaaba16 podman: T6598: add custom podman build for version 4.9.5 2024-07-23 08:03:07 +02:00
Christian Breunig
12e531194d Kernel: T5887: update Linux Kernel to v6.6.41 2024-07-20 09:36:01 +02:00
Christian Breunig
303ba89c14 Kernel: T5887: update Linux Kernel to v6.6.40 2024-07-17 08:47:27 +02:00
Christian Breunig
022bb44588 Kernel: T5887: update Linux Kernel to v6.6.39 2024-07-12 14:47:09 +02:00
Christian Breunig
16753c9d3a
Merge pull request #690 from c-po/podman
container: T5867: pin specific podman version
2024-07-08 17:00:22 +02:00
Christian Breunig
0094dc2ecc container: T5867: pin specific podman version
As of Debian version 4.9.5+ds1-1 podman increased the dependency on
libc6 and libgpgme11t64.

  podman : Depends: libc6 (>= 2.38) but 2.36-9+deb12u7 is to be installed
           Depends: libgpgme11t64 (>= 1.4.1) but it is not going to be installed

Pin the version to a prior one that requires the old libc.
2024-07-08 10:13:08 +02:00
Christian Breunig
2e6e43ee71
Kernel: T5887: update Linux Kernel to v6.6.37 2024-07-06 09:45:52 +02:00
Christian Breunig
dd322145be Kernel: T5887: update Linux Kernel to v6.6.36 2024-07-02 21:46:01 +02:00
Christian Breunig
ff75b07681 T6527: remove legacy packages 2024-06-30 07:33:00 +02:00
Christian Breunig
057db80447
Merge pull request #667 from c-po/T6507-drop-vyos-world
T6507: remove references to vyos-world package
2024-06-27 16:44:28 +02:00
Christian Breunig
6e0f62a0ca T6507: remove references to vyos-world package
As we got rid of most of the old vyatta packages we can now also discontinue
vyos-world. It only served the purpose of keeping the package list during ISO
build small.
2024-06-22 09:07:05 +02:00
Christian Breunig
0c8ffe63e1 Kernel: T5887: update Linux Kernel to v6.6.35 2024-06-22 08:21:07 +02:00
Christian Breunig
41771586bd Kernel: T5887: update Linux Kernel to v6.6.34 2024-06-17 20:07:32 +02:00
Christian Breunig
2b3d116785
Merge pull request #653 from ZenithTecnologia/current
docker: arm: T6474: Initial support for dynamic arch toml loading
2024-06-15 22:32:13 +02:00
Christian Breunig
f2154b4252
Kernel: T5887: update Linux Kernel to v6.6.33 2024-06-12 21:09:26 +02:00
Leonardo Amaral
c0af57d68c
docker: arm: T6474: Added Salt Project repo for armhf
Signed-off-by: Leonardo Amaral <contato@leonardoamaral.com.br>
2024-06-11 18:04:01 -03:00
John Estabrook
3f42cf0865 migration: T6006: move config.boot.default to vyos-1x 2024-06-05 20:00:59 -05:00
Daniil Baturin
5753b4b624 build: T6414: rename the "iso" flavor to "generic" 2024-05-28 19:33:29 +01:00
Christian Breunig
f3cde18f6f Kernel: T5887: update Linux Kernel to v6.6.32 2024-05-25 17:16:45 +02:00
Christian Breunig
d1852e392e
Merge pull request #629 from c-po/T5887-kernel
Kernel: T5887: update Linux Kernel to v6.6.31
2024-05-19 08:22:04 +02:00
Christian Breunig
20b42272c5 Kernel: T5887: update Linux Kernel to v6.6.31 2024-05-19 08:19:24 +02:00
John Estabrook
04948aa983 T6356: normalize '.., ntp, server' path syntax in config.boot.default 2024-05-16 13:19:02 -05:00