From 7dfe14650a65fdb44888c91a9dfa314839adc51d Mon Sep 17 00:00:00 2001 From: Chris Co Date: Fri, 21 Jan 2022 03:19:53 +0000 Subject: [PATCH 1/4] kernel: Update mariner cert in kernel keyring Signed-off-by: Chris Co --- SPECS/kernel/cbl-mariner-ca-20210127.pem | 29 ------------------------ SPECS/kernel/cbl-mariner-ca-20211013.pem | 29 ++++++++++++++++++++++++ SPECS/kernel/kernel.signatures.json | 2 +- SPECS/kernel/kernel.spec | 7 ++++-- 4 files changed, 35 insertions(+), 32 deletions(-) delete mode 100644 SPECS/kernel/cbl-mariner-ca-20210127.pem create mode 100644 SPECS/kernel/cbl-mariner-ca-20211013.pem diff --git a/SPECS/kernel/cbl-mariner-ca-20210127.pem b/SPECS/kernel/cbl-mariner-ca-20210127.pem deleted file mode 100644 index 7b90650cf18..00000000000 --- a/SPECS/kernel/cbl-mariner-ca-20210127.pem +++ /dev/null @@ -1,29 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFBjCCA+6gAwIBAgITMwAABFzCHaG8uk/QhQABAAAEXDANBgkqhkiG9w0BAQsF -ADB5MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH -UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSMwIQYDVQQD -ExpNaWNyb3NvZnQgVGVzdGluZyBQQ0EgMjAxMDAeFw0yMTAxMjgyMTQ0MjVaFw0y -MjAxMjcyMTQ0MjVaMIGGMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv -bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 -aW9uMTAwLgYDVQQDEydNYXJpbmVyIFNlY3VyZSBCb290KFByb2R1Y3Rpb24gU2ln -bmluZykwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDlDKbGLQsXa/s9 -8dukx0OKHoZRCp5otKK/Av2PrbLA4obLl8rHW5uaSi8OFOEaQ75t/PR0me55CIb/ -W7XN/CTRzUtOd5F+ZjJA04asn+ztxvdF8VVtBexNswvh3wi88Tf6YkKDRzMdYboh -2X8lB2aZxUCa98AL4lfWDB2OxakrLJY3LMpnBcDQ8QuGYhEt3YRFkT5mrWeSqphj -6Q1zRtXcETX6P/Mv0JthF45QwVDJCVuRXpgKY+Ug7fXkANpuDO79UmovyLeBa7mv -Oqke6kiXjdCqWd6VuIQxg1VpKNL8wn132NjCQdSwimvmeO0F2r0gqQ7fpQECJoBk -OwEfEEYhAgMBAAGjggF3MIIBczATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4E -FgQUrrgYstPQgjOv9ptpbKdZJ8nqz1kwRQYDVR0RBD4wPKQ6MDgxHjAcBgNVBAsT -FU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEWMBQGA1UEBRMNNDYwODk3KzQ2NDEyOTAf -BgNVHSMEGDAWgBS/ZaKrb3WjTkWWVwXPOYf0wBUcHDBcBgNVHR8EVTBTMFGgT6BN -hktodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQl -MjBUZXN0aW5nJTIwUENBJTIwMjAxMCgxKS5jcmwwaQYIKwYBBQUHAQEEXTBbMFkG -CCsGAQUFBzAChk1odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRz -L01pY3Jvc29mdCUyMFRlc3RpbmclMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMB -Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQBLbLjVDt5GE8uu2ebkmIZBdyEwGQg/ -2y95ja8yfXvFX2p0SFdz1MTxox2ZiIOONF6MbhTadLRTCGifwvHgTwArsjPnl0jk -4YyMCZsJtQOaRtIn8YVRvoGQ8b7oUXx49JtMx1e+Fu0FR3cpBz0VEKrkPiLAzd0x -sRIRfkRDpgZDonOxugsIdceDu/sveqIMv5SlDtq8y7nh+4V2JQpJFs4dU+xTvAHI -9ntSEGLSnvNoj/Z2oTQEoxY4AcfyT81IGVzokDDyArlkp9dgAePoSEH0scJ4bYiF -fP48iMy8Qx136RQNzQQahsFOQDj9RD2weZXWIOCVWkBvaVIkCnk8XIzf ------END CERTIFICATE----- diff --git a/SPECS/kernel/cbl-mariner-ca-20211013.pem b/SPECS/kernel/cbl-mariner-ca-20211013.pem new file mode 100644 index 00000000000..76865b9a68e --- /dev/null +++ b/SPECS/kernel/cbl-mariner-ca-20211013.pem @@ -0,0 +1,29 @@ +-----BEGIN CERTIFICATE----- +MIIFBjCCA+6gAwIBAgITMwAABO5/lN6NQyelHwABAAAE7jANBgkqhkiG9w0BAQsF +ADB5MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH +UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSMwIQYDVQQD +ExpNaWNyb3NvZnQgVGVzdGluZyBQQ0EgMjAxMDAeFw0yMTEwMTQxNzI4MDVaFw0y +MjEwMTMxNzI4MDVaMIGGMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv +bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 +aW9uMTAwLgYDVQQDEydNYXJpbmVyIFNlY3VyZSBCb290KFByb2R1Y3Rpb24gU2ln +bmluZykwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDF45hTHPQAA7yc +6g3iVuqcQKF51ylCynjUySYqqQha2sQzE7tbJ2egVkW4cfY1UbJsm65i2/VGI1OL +Zia4sRwXRN7toRK5aElYfpsghMgGEaCSPs6915BVqO4WX0jxXswqRZ2CPH+evNCC +hQnOqtjvFCqp7aeQ44b/DpZmaMicL/DwbI4925HWGSYa+/Mp1Fs3yGhP5X75+c9v +w4gJ5KoxcOFRmQEt0c7lOclOi5Np5jys7lrrdmPPbjoALERBatiXj8w72LUZu4+I +970/6jqNEkHeGxqVSPRRNIEZubjvRIfg8uULr8k/Kj8TbznCWoGuaT/9yoVbHhqU +KQMJxxFrAgMBAAGjggF3MIIBczATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4E +FgQUtC1rnigJt7kJfP+emwGUuG6Av5UwRQYDVR0RBD4wPKQ6MDgxHjAcBgNVBAsT +FU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEWMBQGA1UEBRMNNDYwODk3KzQ2ODU5NzAf +BgNVHSMEGDAWgBS/ZaKrb3WjTkWWVwXPOYf0wBUcHDBcBgNVHR8EVTBTMFGgT6BN +hktodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQl +MjBUZXN0aW5nJTIwUENBJTIwMjAxMCgxKS5jcmwwaQYIKwYBBQUHAQEEXTBbMFkG +CCsGAQUFBzAChk1odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRz +L01pY3Jvc29mdCUyMFRlc3RpbmclMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMB +Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQCybuv6kmhT2y97FOLRljLCLvQlBL/E +dxKPDYNFhHCKIUd550yUoUW8XIxSYa+Dmx/1+NYS4Nxql7ecuR4g9+4i0DOmNjYO +NY8epPspIpjUd9OAiKNKJSs2303i2TQojXQcZVeTO89bK3pX+spoACGuEVEuWSdL +q+oPDYZwNTKyobj9wHYO6WXJfcdLPlYZghDjR/WNO5bzvzpi2nn/c4OYvMihLNq0 +5uNO0IB/zquyAaCKbi15v/PqYos1BsT+Yft4zf8ry17yFVBIqJMa2An6Gex7SNWj +jj1S7uBga3oZcTHvR8xv3fmbwfQMIrZRmZrq8xkySxQV7xea0sE7X/pJ +-----END CERTIFICATE----- diff --git a/SPECS/kernel/kernel.signatures.json b/SPECS/kernel/kernel.signatures.json index 6467c37402d..8fc1e440afd 100644 --- a/SPECS/kernel/kernel.signatures.json +++ b/SPECS/kernel/kernel.signatures.json @@ -1,6 +1,6 @@ { "Signatures": { - "cbl-mariner-ca-20210127.pem": "82363cb44e786353936abc2e2d62d9325cacf2d9e9a8ebaf4221ea30a9e0cd7b", + "cbl-mariner-ca-20211013.pem": "5ef124b0924cb1047c111a0ecff1ae11e6ad7cac8d1d9b40f98f99334121f0b0", "config": "ef77017acbe6281ca8c581b48c425cca67578fd1ca3666ccb860b4253b55c507", "config_aarch64": "31bd6c50a9707fd0327a61eed8ac465a06a2aaba6e4a34cadbe704739058b69e", "kernel-5.10.89.1.tar.gz": "e7d4ea0eff5635c8be7c8aa7792da2dc5daee6dff374fafa2ae3cf59159c7c4d", diff --git a/SPECS/kernel/kernel.spec b/SPECS/kernel/kernel.spec index 14ef6abe7ff..99c344e5e39 100644 --- a/SPECS/kernel/kernel.spec +++ b/SPECS/kernel/kernel.spec @@ -4,7 +4,7 @@ Summary: Linux Kernel Name: kernel Version: 5.10.89.1 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 Vendor: Microsoft Corporation Distribution: Mariner @@ -15,7 +15,7 @@ Source0: kernel-%{version}.tar.gz Source1: config Source2: config_aarch64 Source3: sha512hmac-openssl.sh -Source4: cbl-mariner-ca-20210127.pem +Source4: cbl-mariner-ca-20211013.pem Patch0: 0001-clocksource-drivers-hyper-v-Re-enable-VDSO_CLOCKMODE.patch Patch1: CVE-2021-43976.patch Patch2: 0003-export-mmput_async.patch @@ -582,6 +582,9 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg %{_sysconfdir}/bash_completion.d/bpftool %changelog +* Thu Jan 20 2022 Chris Co - 5.10.89.1-2 +- Rotate Mariner cert + * Sun Jan 16 2022 Rachel Menge - 5.10.89.1-1 - Update source to 5.10.89.1 - Address CVE-2021-44733, CVE-2021-45469, CVE-2021-28714, CVE-2021-28715 From cebe61147375df9bcb14ea5c9e44f285cc56fb4a Mon Sep 17 00:00:00 2001 From: Chris Co Date: Fri, 21 Jan 2022 03:20:18 +0000 Subject: [PATCH 2/4] kernel-hyperv: Update mariner cert in kernel keyring Signed-off-by: Chris Co --- .../kernel-hyperv/cbl-mariner-ca-20210127.pem | 29 ------------------- .../kernel-hyperv/cbl-mariner-ca-20211013.pem | 29 +++++++++++++++++++ .../kernel-hyperv.signatures.json | 2 +- SPECS/kernel-hyperv/kernel-hyperv.spec | 7 +++-- 4 files changed, 35 insertions(+), 32 deletions(-) delete mode 100644 SPECS/kernel-hyperv/cbl-mariner-ca-20210127.pem create mode 100644 SPECS/kernel-hyperv/cbl-mariner-ca-20211013.pem diff --git a/SPECS/kernel-hyperv/cbl-mariner-ca-20210127.pem b/SPECS/kernel-hyperv/cbl-mariner-ca-20210127.pem deleted file mode 100644 index 7b90650cf18..00000000000 --- a/SPECS/kernel-hyperv/cbl-mariner-ca-20210127.pem +++ /dev/null @@ -1,29 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFBjCCA+6gAwIBAgITMwAABFzCHaG8uk/QhQABAAAEXDANBgkqhkiG9w0BAQsF -ADB5MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH -UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSMwIQYDVQQD -ExpNaWNyb3NvZnQgVGVzdGluZyBQQ0EgMjAxMDAeFw0yMTAxMjgyMTQ0MjVaFw0y -MjAxMjcyMTQ0MjVaMIGGMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv -bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 -aW9uMTAwLgYDVQQDEydNYXJpbmVyIFNlY3VyZSBCb290KFByb2R1Y3Rpb24gU2ln -bmluZykwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDlDKbGLQsXa/s9 -8dukx0OKHoZRCp5otKK/Av2PrbLA4obLl8rHW5uaSi8OFOEaQ75t/PR0me55CIb/ -W7XN/CTRzUtOd5F+ZjJA04asn+ztxvdF8VVtBexNswvh3wi88Tf6YkKDRzMdYboh -2X8lB2aZxUCa98AL4lfWDB2OxakrLJY3LMpnBcDQ8QuGYhEt3YRFkT5mrWeSqphj -6Q1zRtXcETX6P/Mv0JthF45QwVDJCVuRXpgKY+Ug7fXkANpuDO79UmovyLeBa7mv -Oqke6kiXjdCqWd6VuIQxg1VpKNL8wn132NjCQdSwimvmeO0F2r0gqQ7fpQECJoBk -OwEfEEYhAgMBAAGjggF3MIIBczATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4E -FgQUrrgYstPQgjOv9ptpbKdZJ8nqz1kwRQYDVR0RBD4wPKQ6MDgxHjAcBgNVBAsT -FU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEWMBQGA1UEBRMNNDYwODk3KzQ2NDEyOTAf -BgNVHSMEGDAWgBS/ZaKrb3WjTkWWVwXPOYf0wBUcHDBcBgNVHR8EVTBTMFGgT6BN -hktodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQl -MjBUZXN0aW5nJTIwUENBJTIwMjAxMCgxKS5jcmwwaQYIKwYBBQUHAQEEXTBbMFkG -CCsGAQUFBzAChk1odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRz -L01pY3Jvc29mdCUyMFRlc3RpbmclMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMB -Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQBLbLjVDt5GE8uu2ebkmIZBdyEwGQg/ -2y95ja8yfXvFX2p0SFdz1MTxox2ZiIOONF6MbhTadLRTCGifwvHgTwArsjPnl0jk -4YyMCZsJtQOaRtIn8YVRvoGQ8b7oUXx49JtMx1e+Fu0FR3cpBz0VEKrkPiLAzd0x -sRIRfkRDpgZDonOxugsIdceDu/sveqIMv5SlDtq8y7nh+4V2JQpJFs4dU+xTvAHI -9ntSEGLSnvNoj/Z2oTQEoxY4AcfyT81IGVzokDDyArlkp9dgAePoSEH0scJ4bYiF -fP48iMy8Qx136RQNzQQahsFOQDj9RD2weZXWIOCVWkBvaVIkCnk8XIzf ------END CERTIFICATE----- diff --git a/SPECS/kernel-hyperv/cbl-mariner-ca-20211013.pem b/SPECS/kernel-hyperv/cbl-mariner-ca-20211013.pem new file mode 100644 index 00000000000..76865b9a68e --- /dev/null +++ b/SPECS/kernel-hyperv/cbl-mariner-ca-20211013.pem @@ -0,0 +1,29 @@ +-----BEGIN CERTIFICATE----- +MIIFBjCCA+6gAwIBAgITMwAABO5/lN6NQyelHwABAAAE7jANBgkqhkiG9w0BAQsF +ADB5MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMH +UmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSMwIQYDVQQD +ExpNaWNyb3NvZnQgVGVzdGluZyBQQ0EgMjAxMDAeFw0yMTEwMTQxNzI4MDVaFw0y +MjEwMTMxNzI4MDVaMIGGMQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv +bjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0 +aW9uMTAwLgYDVQQDEydNYXJpbmVyIFNlY3VyZSBCb290KFByb2R1Y3Rpb24gU2ln +bmluZykwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDF45hTHPQAA7yc +6g3iVuqcQKF51ylCynjUySYqqQha2sQzE7tbJ2egVkW4cfY1UbJsm65i2/VGI1OL +Zia4sRwXRN7toRK5aElYfpsghMgGEaCSPs6915BVqO4WX0jxXswqRZ2CPH+evNCC +hQnOqtjvFCqp7aeQ44b/DpZmaMicL/DwbI4925HWGSYa+/Mp1Fs3yGhP5X75+c9v +w4gJ5KoxcOFRmQEt0c7lOclOi5Np5jys7lrrdmPPbjoALERBatiXj8w72LUZu4+I +970/6jqNEkHeGxqVSPRRNIEZubjvRIfg8uULr8k/Kj8TbznCWoGuaT/9yoVbHhqU +KQMJxxFrAgMBAAGjggF3MIIBczATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4E +FgQUtC1rnigJt7kJfP+emwGUuG6Av5UwRQYDVR0RBD4wPKQ6MDgxHjAcBgNVBAsT +FU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjEWMBQGA1UEBRMNNDYwODk3KzQ2ODU5NzAf +BgNVHSMEGDAWgBS/ZaKrb3WjTkWWVwXPOYf0wBUcHDBcBgNVHR8EVTBTMFGgT6BN +hktodHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NybC9NaWNyb3NvZnQl +MjBUZXN0aW5nJTIwUENBJTIwMjAxMCgxKS5jcmwwaQYIKwYBBQUHAQEEXTBbMFkG +CCsGAQUFBzAChk1odHRwOi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL2NlcnRz +L01pY3Jvc29mdCUyMFRlc3RpbmclMjBQQ0ElMjAyMDEwKDEpLmNydDAMBgNVHRMB +Af8EAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQCybuv6kmhT2y97FOLRljLCLvQlBL/E +dxKPDYNFhHCKIUd550yUoUW8XIxSYa+Dmx/1+NYS4Nxql7ecuR4g9+4i0DOmNjYO +NY8epPspIpjUd9OAiKNKJSs2303i2TQojXQcZVeTO89bK3pX+spoACGuEVEuWSdL +q+oPDYZwNTKyobj9wHYO6WXJfcdLPlYZghDjR/WNO5bzvzpi2nn/c4OYvMihLNq0 +5uNO0IB/zquyAaCKbi15v/PqYos1BsT+Yft4zf8ry17yFVBIqJMa2An6Gex7SNWj +jj1S7uBga3oZcTHvR8xv3fmbwfQMIrZRmZrq8xkySxQV7xea0sE7X/pJ +-----END CERTIFICATE----- diff --git a/SPECS/kernel-hyperv/kernel-hyperv.signatures.json b/SPECS/kernel-hyperv/kernel-hyperv.signatures.json index 39476e9a300..f4c4cb539db 100644 --- a/SPECS/kernel-hyperv/kernel-hyperv.signatures.json +++ b/SPECS/kernel-hyperv/kernel-hyperv.signatures.json @@ -1,6 +1,6 @@ { "Signatures": { - "cbl-mariner-ca-20210127.pem": "82363cb44e786353936abc2e2d62d9325cacf2d9e9a8ebaf4221ea30a9e0cd7b", + "cbl-mariner-ca-20211013.pem": "5ef124b0924cb1047c111a0ecff1ae11e6ad7cac8d1d9b40f98f99334121f0b0", "config": "4963022eb4ebdf0561ed64f60291949fa16e212dc2dcdb2e481978241c5548ae", "kernel-5.10.89.1.tar.gz": "e7d4ea0eff5635c8be7c8aa7792da2dc5daee6dff374fafa2ae3cf59159c7c4d", "sha512hmac-openssl.sh": "02ab91329c4be09ee66d759e4d23ac875037c3b56e5a598e32fd1206da06a27f" diff --git a/SPECS/kernel-hyperv/kernel-hyperv.spec b/SPECS/kernel-hyperv/kernel-hyperv.spec index 84333d550a2..3c5a8d51a99 100644 --- a/SPECS/kernel-hyperv/kernel-hyperv.spec +++ b/SPECS/kernel-hyperv/kernel-hyperv.spec @@ -4,7 +4,7 @@ Summary: Linux Kernel optimized for Hyper-V Name: kernel-hyperv Version: 5.10.89.1 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 Vendor: Microsoft Corporation Distribution: Mariner @@ -14,7 +14,7 @@ URL: https://github.com/microsoft/CBL-Mariner-Linux-Kernel Source0: kernel-%{version}.tar.gz Source1: config Source2: sha512hmac-openssl.sh -Source3: cbl-mariner-ca-20210127.pem +Source3: cbl-mariner-ca-20211013.pem Patch0: 0001-clocksource-drivers-hyper-v-Re-enable-VDSO_CLOCKMODE.patch Patch1: CVE-2021-43976.patch BuildRequires: audit-devel @@ -271,6 +271,9 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg %{_libdir}/perf/include/bpf/* %changelog +* Thu Jan 20 2022 Chris Co - 5.10.89.1-2 +- Rotate Mariner cert + * Sun Jan 16 2022 Rachel Menge - 5.10.89.1-1 - Update source to 5.10.89.1 - Remove patch add-linux-syscall-license-info.patch From dcf6e70ef7c90cae319f87410a0d0f89a6889d41 Mon Sep 17 00:00:00 2001 From: Chris Co Date: Fri, 21 Jan 2022 03:22:42 +0000 Subject: [PATCH 3/4] kernel-headers: Bump to match kernel release number Signed-off-by: Chris Co --- SPECS/kernel-headers/kernel-headers.spec | 5 ++++- toolkit/resources/manifests/package/pkggen_core_aarch64.txt | 2 +- toolkit/resources/manifests/package/pkggen_core_x86_64.txt | 2 +- toolkit/resources/manifests/package/toolchain_aarch64.txt | 2 +- toolkit/resources/manifests/package/toolchain_x86_64.txt | 2 +- 5 files changed, 8 insertions(+), 5 deletions(-) diff --git a/SPECS/kernel-headers/kernel-headers.spec b/SPECS/kernel-headers/kernel-headers.spec index af15034c430..17a01ef9ce6 100644 --- a/SPECS/kernel-headers/kernel-headers.spec +++ b/SPECS/kernel-headers/kernel-headers.spec @@ -1,7 +1,7 @@ Summary: Linux API header files Name: kernel-headers Version: 5.10.89.1 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 Vendor: Microsoft Corporation Distribution: Mariner @@ -39,6 +39,9 @@ cp -rv usr/include/* /%{buildroot}%{_includedir} %{_includedir}/* %changelog +* Thu Jan 20 2022 Chris Co - 5.10.89.1-2 +- Bump release number to match kernel release + * Sun Jan 16 2022 Rachel Menge - 5.10.89.1-1 - Update source to 5.10.89.1 - Remove patch add-linux-syscall-license-info.patch diff --git a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt index ee32980bb61..8969f448ac9 100644 --- a/toolkit/resources/manifests/package/pkggen_core_aarch64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_aarch64.txt @@ -1,5 +1,5 @@ filesystem-1.1-7.cm1.aarch64.rpm -kernel-headers-5.10.89.1-1.cm1.noarch.rpm +kernel-headers-5.10.89.1-2.cm1.noarch.rpm glibc-2.28-22.cm1.aarch64.rpm glibc-devel-2.28-22.cm1.aarch64.rpm glibc-i18n-2.28-22.cm1.aarch64.rpm diff --git a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt index 3edf644da81..5bcaffc238e 100644 --- a/toolkit/resources/manifests/package/pkggen_core_x86_64.txt +++ b/toolkit/resources/manifests/package/pkggen_core_x86_64.txt @@ -1,5 +1,5 @@ filesystem-1.1-7.cm1.x86_64.rpm -kernel-headers-5.10.89.1-1.cm1.noarch.rpm +kernel-headers-5.10.89.1-2.cm1.noarch.rpm glibc-2.28-22.cm1.x86_64.rpm glibc-devel-2.28-22.cm1.x86_64.rpm glibc-i18n-2.28-22.cm1.x86_64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_aarch64.txt b/toolkit/resources/manifests/package/toolchain_aarch64.txt index a146a4be406..bc2e745ae9a 100644 --- a/toolkit/resources/manifests/package/toolchain_aarch64.txt +++ b/toolkit/resources/manifests/package/toolchain_aarch64.txt @@ -155,7 +155,7 @@ json-c-debuginfo-0.14-3.cm1.aarch64.rpm json-c-devel-0.14-3.cm1.aarch64.rpm kbd-2.0.4-6.cm1.aarch64.rpm kbd-debuginfo-2.0.4-6.cm1.aarch64.rpm -kernel-headers-5.10.89.1-1.cm1.noarch.rpm +kernel-headers-5.10.89.1-2.cm1.noarch.rpm kmod-25-4.cm1.aarch64.rpm kmod-debuginfo-25-4.cm1.aarch64.rpm kmod-devel-25-4.cm1.aarch64.rpm diff --git a/toolkit/resources/manifests/package/toolchain_x86_64.txt b/toolkit/resources/manifests/package/toolchain_x86_64.txt index c4de6dd274a..54e6b7b9975 100644 --- a/toolkit/resources/manifests/package/toolchain_x86_64.txt +++ b/toolkit/resources/manifests/package/toolchain_x86_64.txt @@ -155,7 +155,7 @@ json-c-debuginfo-0.14-3.cm1.x86_64.rpm json-c-devel-0.14-3.cm1.x86_64.rpm kbd-2.0.4-6.cm1.x86_64.rpm kbd-debuginfo-2.0.4-6.cm1.x86_64.rpm -kernel-headers-5.10.89.1-1.cm1.noarch.rpm +kernel-headers-5.10.89.1-2.cm1.noarch.rpm kmod-25-4.cm1.x86_64.rpm kmod-debuginfo-25-4.cm1.x86_64.rpm kmod-devel-25-4.cm1.x86_64.rpm From ebb8e48367c0c37c631e56d3d5d3fe1cea92052f Mon Sep 17 00:00:00 2001 From: Chris Co Date: Fri, 21 Jan 2022 03:23:13 +0000 Subject: [PATCH 4/4] kernel-signed: Bump to match kernel release Signed-off-by: Chris Co --- SPECS-SIGNED/kernel-signed/kernel-signed.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/SPECS-SIGNED/kernel-signed/kernel-signed.spec b/SPECS-SIGNED/kernel-signed/kernel-signed.spec index 0886de698f7..3c8f7d1babc 100644 --- a/SPECS-SIGNED/kernel-signed/kernel-signed.spec +++ b/SPECS-SIGNED/kernel-signed/kernel-signed.spec @@ -10,7 +10,7 @@ Summary: Signed Linux Kernel for %{buildarch} systems Name: kernel-signed-%{buildarch} Version: 5.10.89.1 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 Vendor: Microsoft Corporation Distribution: Mariner @@ -147,6 +147,9 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg %endif %changelog +* Thu Jan 20 2022 Chris Co - 5.10.89.1-2 +- Bump release number to match kernel release + * Sun Jan 16 2022 Rachel Menge - 5.10.89.1-1 - Update source to 5.10.89.1