-
Notifications
You must be signed in to change notification settings - Fork 625
merge 1.0 into dev #299
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
merge 1.0 into dev #299
Changes from all commits
Commits
Show all changes
133 commits
Select commit
Hold shift + click to select a range
ff4b770
Update trademark section of the readme
jperrin 09940d6
Update building.md (#104)
jasongos 83de3e2
add wants=sshd-keygen.service to sshd (#58)
jperrin 7126e0b
Fix libffi normal package build (#116)
MateuszMalisz 070331f
Upgrade golang to 1.13.15 (#93)
niontive 4e504e3
Adding a small build tip to the quick start instructions. (#123)
PawelWMS 5197a48
Add cloud-init-vmware-guestinfo package (#124)
MateuszMalisz 0bfe2f9
Updating 'ca-certificates' nssckbi.h header and unifying changelog en…
PawelWMS b3d7496
Markdown lint-induced clean-up of doc files. (#122)
PawelWMS 6068d8b
Add IMA feature to the kernel, add config for it (#135)
dmcilvaney 4b56414
Update tpm2 tools to 4.2, tss to 2.4.0 (#134)
dmcilvaney 4c83bb0
Enable Mellanox kernel configs
chalamalasetty 32a0787
Update tpm2-abrmd to 2.3.3 (#144)
dmcilvaney b3ea131
Create quickstart.yml (#119)
christopherco 486f4fc
Nopatch httpd CVE-1999-0236, CVE-1999-1412 (#148)
dmcilvaney a7ae423
Nopatch groff CVE-2000-0803 (#149)
dmcilvaney 4f331e7
Nopatch apparmor CVE-2016-1585 (#150)
dmcilvaney d04ebb2
Nopatch qemu CVE-2016-7161 (#152)
dmcilvaney f4528b8
Nopatch lua CVE-2020-15889 (#153)
dmcilvaney 10cdad0
Nopatch unzip CVE-2008-0888 (#154)
dmcilvaney 5e3844e
full: Always install the default kernel (#132)
christopherco b556e4d
Merge pull request #142 from microsoft/schalam/mlx_sr-iov
chalamalasetty b5564be
Support downloading preview SRPMs (#160)
schmittjoseph adf08fb
Patch CVE-2020-14342 in cifs-utils
hbeberman 9115bc4
Replace mariner-repos's %post script as %posttrans
mrgirgin c3ccb82
Update pkggen_core_aarch64.txt
mrgirgin 41a6c75
Update pkggen_core_x86_64.txt
mrgirgin 8756d18
Update toolchain_aarch64.txt
mrgirgin 1a1ed8c
Update toolchain_x86_64.txt
mrgirgin 00ea862
Add a more verbose changelog
mrgirgin 906693b
Remove chrony-wait as a boot service dependency (#166)
oliviacrain 9c3499f
Address changelog and prep section comments
hbeberman e95dc98
Merge branch '1.0-dev' into 1.0
jslobodzian 49b0a95
initramfs: Regenerate initrd using host-only mode on file-based trigg…
christopherco f86fe91
Fix kernel specs' %postun scripts (#164)
mrgirgin 563639e
Merge branch '1.0-dev' into 1.0
jslobodzian 4826b65
Adding new 'preview' repository. (#146)
PawelWMS 69a5be2
Merge branch '1.0-dev' into mrgirgin/mariner-repos-post
c6ccffa
Fix kernel aarch64 package build break due to missing CONFIG_IMA_KEXE…
christopherco c5d866a
Merge pull request #167 from microsoft/mrgirgin/mariner-repos-post
mrgirgin 6e9a239
Fix kernel aarch64 package build break due to missing CONFIG_IMA_KEXE…
christopherco e9fead7
Update fontconfig to 2.13.91 (#175)
MateuszMalisz 3169bfd
Extending 'strongswan' test timeout. (#173)
PawelWMS e3880ed
Fix CVE-2020-14342 patch to not depend on PATH
hbeberman 328cd7b
installutils: Supply blank /etc/machine-id file (#147)
christopherco d6a2628
installutils: Remove root password expiry when no root user is specif…
christopherco b2d918e
Add SELinux packages to Mariner. (#100)
dburgener 0181cc7
Remove "::set-env" commands in GitHub Actions (#178)
oliviacrain 0bec6a1
Adding a .nopatch for CVE-2007-0086. (#176)
PawelWMS 9e6952f
Updating cert bundle paths. (#181)
PawelWMS 71ce404
Adding the `gflags` and `rocksdb` packages. (#183)
PawelWMS 9cff088
Add missing %libsepolver definition in secilc.spec (#192)
oliviacrain 397c1f0
Removing 'TERMINAL_ISO_INSTALLER' from the docs. (#189)
PawelWMS ce47c3d
Merge pull request #165 from hbeberman/cifs_utils_fix
hbeberman c0faafa
Add architecture at the end of toolkit archive (#182)
mrgirgin d5101f4
Adding a missing '%{?dist}' tag. (#195)
PawelWMS c1ce898
enable fetching RPMs from pacakges.microsoft.com for Docker based bui…
nicogbg 110619a
Update README.md (#180)
78d83a1
Update README.md (#180)
791c4b9
Build Break Fix: Rollback selinux checkins. (#204)
jslobodzian e955239
Natively support pulling from the preview repo (#199)
schmittjoseph d7c5db2
Fix CVE-2020-26159 in oniguruma (#211)
mrgirgin 228dc7d
Adding the 'syslog-ng' package. (#205)
PawelWMS d8e7691
Adding the 'tinyxml2' package. (#206)
PawelWMS c2c7f85
Adding the 'toml11' package. (#207)
PawelWMS a7682dd
Adding the 'tracelogging' and 'zipper' packages. (#208)
PawelWMS c42ddb8
Add mm-common and libxml++ packages (#215)
oliviacrain 010d470
Add liblogging package (#214)
oliviacrain 329cf32
Add nlohmann-json package (#217)
oliviacrain 6df1d23
Add msgpack package (#216)
oliviacrain 3312d37
Adding the 'span-lite' and 'telegraf' packages. (#220)
PawelWMS 511ee60
Remove toolchain-local-wget-list after use (#212)
mrgirgin 61bf241
Remove implicit git repository dependency from toolkit (#197)
mrgirgin f213e1f
Add jsonbuilder package (#223)
oliviacrain cb25057
update libffi to use https source0 (#227)
anphel31 5fc0ddb
Update libestr (#213)
oliviacrain d3b01bd
Add babeltrace2 and lttng-consume packages (#226)
oliviacrain 916b6f7
Add pugixml package (#222)
oliviacrain 4715660
Disable debug package for nlohmann-json (#228)
oliviacrain 0eb5d55
Add rapidjson package (#225)
oliviacrain 89fec18
Upgrade ruby to 2.6.6 to resolve CVE-2019-16255, CVE-2019-16201, CVE-…
mrgirgin 9f37952
Nopatch qemu CVE-2015-7504 CVE-2017-5931 CVE-2017-14167 (#162)
dmcilvaney 1deb334
Fix CVE-2020-26159 in oniguruma (#211)
mrgirgin c5ecb62
Enable QAT kernel configs in CBL-Mariner
chalamalasetty b354cbf
Nopatch kernel CVE-2020-10757, CVE-2020-12653, CVE-2020-12657, CVE-20…
christopherco 6ea7fde
Adding the `bond`, `fluent-bit`, and `ivykis` packages. (#234)
PawelWMS d8a4371
Joslobo/add azure storage (#232)
jslobodzian 99ec27a
Initial spec lint action commit (#172) (#191)
oliviacrain b54a5a8
Merge branch '1.0-dev' into schalam/qatengine
chalamalasetty 3b5441a
patch openssh (#238)
anphel31 bcf0e59
Update pull_request_template.md (#236)
mrgirgin e602122
Fix check tests for git, make, krb5 and libcap-ng (#241)
anphel31 2ae22e2
Fix CVE-2019-12735 in vim (#230)
mrgirgin 627798a
Merge pull request #233 from microsoft/schalam/qatengine
chalamalasetty 9af371f
Switching to correct source for the Microsoft bundle. (#244)
PawelWMS 84903e9
Fix check tests for brotli, gzip and python-certifi (#245)
anphel31 5303d09
Patch unbound CVE-2020-12662 and CVE-2020-12663 (#246)
schmittjoseph 1a31576
Portablectl patches for to support --now --enable and --no-block flag…
chalamalasetty d6586ff
Patch lua CVE-2019-6706, CVE-2020-15888, nopatch CVE-2020-24342 (#169)
dmcilvaney 7f1c1fe
Nopatch ed CVE-2015-2987 (#209)
hbeberman 4d498ef
Patch gnutls CVE-2020-24659 (#247)
hbeberman af2bb11
update ant verision
henryli001 b92bed7
fix changelog comment
henryli001 a400f02
update cgmanifest
henryli001 8aca46a
Merge pull request #253 from microsoft/lihl/ant-CVE-2020-11979
henryli001 01d594a
Nopatch sqlite CVE-2015-3717 (#254)
rychenf1 f95e72e
Added omi package
nisamson 8397380
Merge pull request #259 from microsoft/nisamson/add-omi
nisamson 56ad164
Adding the `ccache` and `clamav` packages. (#251)
PawelWMS 45ce54e
Generate ant signatures (#260)
schmittjoseph a42f887
Add auoms package (#258)
anphel31 e41efdd
Implement "distroless" containers (#252)
MateuszMalisz 71e34ba
Updated mariner-release package version (#262)
jslobodzian 1129ca1
fix setup (#263)
anphel31 e9af376
Merge branch '1.0-dev' into 1.0 for October Update
jslobodzian e10f52e
fix missed merge file
jslobodzian 08fe4cc
Fixed bad file merge
jslobodzian 5df20d4
Fixed poorly merged files
jslobodzian fefbf5f
Merge distroless container revert to 1.0 (#265)
jslobodzian deeac8f
Merge branch 'dev' into anphel/merge_1.0_dev_oct28
anphel31 13b8327
fix package manifest merge issues
anphel31 39302d3
fix issues building input-srpms
anphel31 c2c2f3f
fix package manifest issues
anphel31 4fba0b2
remove duplicate patch and sed cmd from lua spec
anphel31 803d496
revert package ignore list and graphoptimizer changes
anphel31 c46249d
remove runc from LICENSES-MAP.md
anphel31 b013b5a
Update pkggen merge (#316)
schmittjoseph f687fee
Clean up lua.spec 1.0 to dev merge (#318)
dmcilvaney 3718261
update lua.spec and licenses-map.md per feedback
anphel31 995f6a3
revert gzip changes
anphel31 70a992b
revert krb5 change
anphel31 a899758
Merge branch 'dev' into anphel/merge_1.0_dev_oct28
anphel31 8c8fe1f
Merge branch 'dev' into anphel/merge_1.0_dev_oct28
anphel31 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,80 @@ | ||
| # Copyright (c) Microsoft Corporation. | ||
| # Licensed under the MIT License. | ||
| # | ||
| # Workflow to automatedly verify the quickstart instructions | ||
|
|
||
| name: Verify Quickstart | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
| schedule: | ||
| - cron: "0 15 * * *" | ||
|
|
||
| jobs: | ||
| iso_quickstart: | ||
| runs-on: ubuntu-18.04 | ||
|
|
||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v2.3.2 | ||
| with: | ||
| ref: '1.0-stable' | ||
|
|
||
| - name: Set up Go 1.13 | ||
| uses: actions/setup-go@v2 | ||
| with: | ||
| go-version: 1.13 | ||
| id: go | ||
|
|
||
| - name: Install Remaining Prerequisites | ||
| run: | | ||
| # Golang and docker are already installed on the agent | ||
| sudo apt-get update | ||
| sudo apt -y install make tar wget curl rpm qemu-utils genisoimage pigz | ||
|
|
||
| - name: Configure the Environment | ||
| run: | | ||
| pushd toolkit | ||
| sudo make go-tools REBUILD_TOOLS=y | ||
| sudo make input-srpms DOWNLOAD_SRPMS=y | ||
| popd | ||
|
|
||
| - name: ISO Quick Start | ||
| run: | | ||
| pushd toolkit | ||
| sudo make iso REBUILD_TOOLS=y REBUILD_PACKAGES=n | ||
| popd | ||
|
|
||
| vhdx_quickstart: | ||
| runs-on: ubuntu-18.04 | ||
|
|
||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v2.3.2 | ||
| with: | ||
| ref: '1.0-stable' | ||
|
|
||
| - name: Set up Go 1.13 | ||
| uses: actions/setup-go@v2 | ||
| with: | ||
| go-version: 1.13 | ||
| id: go | ||
|
|
||
| - name: Install Remaining Prerequisites | ||
| run: | | ||
| # Golang and docker are already installed on the agent | ||
| sudo apt-get update | ||
| sudo apt -y install make tar wget curl rpm qemu-utils genisoimage pigz | ||
|
|
||
| - name: Configure Environment | ||
| run: | | ||
| pushd toolkit | ||
| sudo make go-tools REBUILD_TOOLS=y | ||
| sudo make input-srpms DOWNLOAD_SRPMS=y | ||
| popd | ||
|
|
||
| - name: VHDX Quick Start | ||
| run: | | ||
| pushd toolkit | ||
| sudo make image REBUILD_TOOLS=y REBUILD_PACKAGES=n | ||
| popd |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| # CVE-2016-1585 has no upstream fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.