Skip to content

Commit fdcc9d9

Browse files
authored
Merge pull request #4438 from microsoft/sammeluch/merge-crit-high-cve-fixes
Merge High or Critical CVE Fixes to 2.0 for sqlite, python3, kernel, and nodejs and an update to k3s Vendor Tarball for Dependencies.
2 parents 32cf2a2 + a8d9c5c commit fdcc9d9

File tree

66 files changed

+16167
-107
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

66 files changed

+16167
-107
lines changed

SPECS-SIGNED/kernel-hci-signed/kernel-hci-signed.spec

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
%define uname_r %{version}-%{release}
55
Summary: Signed Linux Kernel for HCI
66
Name: kernel-hci-signed-%{buildarch}
7-
Version: 5.15.80.1
7+
Version: 5.15.82.1
88
Release: 1%{?dist}
99
License: GPLv2
1010
Vendor: Microsoft Corporation
@@ -149,6 +149,12 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg
149149
%exclude /module_info.ld
150150

151151
%changelog
152+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
153+
- Auto-upgrade to 5.15.82.1
154+
155+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
156+
- Auto-upgrade to 5.15.81.1
157+
152158
* Tue Nov 29 2022 Vince Perri <[email protected]> - 5.15.80.1-1
153159
- Original version for CBL-Mariner.
154160
- License verified

SPECS-SIGNED/kernel-signed/kernel-signed.spec

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
%define uname_r %{version}-%{release}
1010
Summary: Signed Linux Kernel for %{buildarch} systems
1111
Name: kernel-signed-%{buildarch}
12-
Version: 5.15.80.1
12+
Version: 5.15.82.1
1313
Release: 1%{?dist}
1414
License: GPLv2
1515
Vendor: Microsoft Corporation
@@ -153,6 +153,15 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg
153153
%exclude /module_info.ld
154154

155155
%changelog
156+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
157+
- Auto-upgrade to 5.15.82.1
158+
159+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
160+
- Auto-upgrade to 5.15.81.1
161+
162+
* Mon Dec 05 2022 Betty Lakes <[email protected]> - 5.15.80.1-2
163+
- Bump release to match kernel
164+
156165
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
157166
- Auto-upgrade to 5.15.80.1
158167

SPECS/LICENSES-AND-NOTICES/LICENSES-MAP.md

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

SPECS/LICENSES-AND-NOTICES/data/licenses.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2047,6 +2047,8 @@
20472047
"livepatch-5.15.77.1-1.cm2-signed",
20482048
"livepatch-5.15.79.1-1.cm2",
20492049
"livepatch-5.15.80.1-1.cm2",
2050+
"livepatch-5.15.81.1-1.cm2",
2051+
"livepatch-5.15.82.1-1.cm2",
20502052
"livepatching",
20512053
"lld",
20522054
"local-path-provisioner",

SPECS/hyperv-daemons/hyperv-daemons.signatures.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,6 @@
77
"hypervkvpd.service": "c1bb207cf9f388f8f3cf5b649abbf8cfe4c4fcf74538612946e68f350d1f265f",
88
"hypervvss.rules": "94cead44245ef6553ab79c0bbac8419e3ff4b241f01bcec66e6f508098cbedd1",
99
"hypervvssd.service": "22270d9f0f23af4ea7905f19c1d5d5495e40c1f782cbb87a99f8aec5a011078d",
10-
"kernel-5.15.80.1.tar.gz": "690c866bf52eb1afa660820d24893d799372b887963b3a6653551dea7a5466b5"
10+
"kernel-5.15.82.1.tar.gz": "30a0059b18ea04469340c6e9e21d27786692faf05b3947e3eb13d62e25632b15"
1111
}
1212
}

SPECS/hyperv-daemons/hyperv-daemons.spec

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
%global udev_prefix 70
99
Summary: Hyper-V daemons suite
1010
Name: hyperv-daemons
11-
Version: 5.15.80.1
11+
Version: 5.15.82.1
1212
Release: 1%{?dist}
1313
License: GPLv2+
1414
Vendor: Microsoft Corporation
@@ -219,6 +219,12 @@ fi
219219
%{_sbindir}/lsvmbus
220220

221221
%changelog
222+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
223+
- Auto-upgrade to 5.15.82.1
224+
225+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
226+
- Auto-upgrade to 5.15.81.1
227+
222228
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
223229
- Auto-upgrade to 5.15.80.1
224230

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
3-
"k3s-1.23.8-vendor.tar.gz": "3c96e864d0e89e318ecdd62e1750f787d1b622feeb240f7b86d9f3280447aeda",
3+
"k3s-1.23.8-vendor.tar.gz": "f6a8ca7fac181a606cf2ef0f09947160ab6037885c08fc8855249c7976762d11",
44
"k3s-1.23.8.tar.gz": "35ff7b3819cf9ff3b33497e335ccfd892a642acd4c5e4223585d225f11fe4b64"
55
}
66
}

SPECS/k3s/k3s-1.23.8.spec

Lines changed: 11 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,23 @@
11
Summary: Lightweight Kubernetes
22
Name: k3s
33
Version: 1.23.8
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: ASL 2.0
66
Group: System Environment/Base
77
URL: http://k3s.io
8-
Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+k3s1.tar.gz#/%{name}-%{version}.tar.gz
8+
Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+k3s2.tar.gz#/%{name}-%{version}.tar.gz
99
# Below is a manually created tarball, no download link.
1010
# We're using pre-populated Go modules from this tarball, since network is disabled during build time.
1111
# We are also pre-cloning 3 git repositories
1212
# How to re-build this file:
13-
# 1. wget https://github.com/k3s-io/%%{name}/archive/refs/tags/v%%{version}+k3s1.tar.gz -O %%{name}-%%{version}.tar.gz
13+
# 1. wget https://github.com/k3s-io/%%{name}/archive/refs/tags/v%%{version}+k3s2.tar.gz -O %%{name}-%%{version}.tar.gz
1414
# 2. tar -xf %%{name}-%%{version}.tar.gz
15-
# 3. cd %%{name}-%%{version}-k3s1
15+
# 3. cd %%{name}-%%{version}-k3s2
1616
# 4. go mod vendor
1717
# 5. pushd vendor
18-
# 6. git clone https://github.com/k3s-io/containerd -b v1.5.13-k3s1
19-
# 7. git clone https://github.com/rancher/plugins.git -b k3s-v1.1.1
20-
# 8. git clone https://github.com/opencontainers/runc.git -b v1.1.2
18+
# 6. git clone --single-branch --branch="v1.5.13-k3s1" --depth=1 https://github.com/k3s-io/containerd
19+
# 7. git clone -b "v1.1.1-k3s1" https://github.com/rancher/plugins.git
20+
# 8. git clone --single-branch --branch="v1.1.2" --depth=1 https://github.com/opencontainers/runc
2121
# 9. popd
2222
# 10. tar -cf %%{name}-%%{version}-vendor.tar.gz vendor
2323
Source1: %{name}-%{version}-vendor.tar.gz
@@ -79,6 +79,9 @@ exit 0
7979
%{install_sh}
8080

8181
%changelog
82+
* Thu Dec 08 2022 Vinayak Gupta <[email protected]> - 1.23.8-3
83+
- Update the vendor tarball with the corrected versions of the dependencies
84+
8285
* Tue Nov 01 2022 Olivia Crain <[email protected]> - 1.23.8-2
8386
- Bump release to rebuild with go 1.18.8
8487

@@ -104,4 +107,4 @@ exit 0
104107
- Initial CBL-Mariner import from Rancher (license: ASL 2.0).
105108

106109
* Mon Mar 2 2020 Erik Wilson <[email protected]> 0.1-1
107-
- Initial version
110+
- Initial version
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
3-
"k3s-1.24.3-vendor.tar.gz": "af12595259cf8a732b687f8341526b680fbc9266c05e4d095f80c75d891a230f",
3+
"k3s-1.24.3-vendor.tar.gz": "5a4b75cb7bcedc96900126e16df985c0c2c7e4e45ea759dd11d487ddcaf71c32",
44
"k3s-1.24.3.tar.gz": "002fd919452e8fbc61182e1cbf90997a1f8b16a7b835e05e7c40bb52bf830f56"
55
}
66
}

SPECS/k3s/k3s-1.24.3.spec

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Summary: Lightweight Kubernetes
22
Name: k3s
33
Version: 1.24.3
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: ASL 2.0
66
Group: System Environment/Base
77
URL: http://k3s.io
@@ -15,9 +15,9 @@ Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+
1515
# 3. cd %%{name}-%%{version}-k3s1
1616
# 4. go mod vendor
1717
# 5. pushd vendor
18-
# 6. git clone https://github.com/k3s.io/containerd.git -b 1.5.13-k3s1
19-
# 7. git clone https://github.com/rancher/plugins.git -b k3s-v1.1.1
20-
# 8. git clone https://github.com/opencontainers/runc.git -b v1.1.3
18+
# 6. git clone --single-branch --branch="v1.6.6-k3s1" --depth=1 https://github.com/k3s-io/containerd
19+
# 7. git clone -b "v1.1.1-k3s1" https://github.com/rancher/plugins.git
20+
# 8. git clone --single-branch --branch="v1.1.3" --depth=1 https://github.com/opencontainers/runc
2121
# 9. popd
2222
# 10. tar -cf %%{name}-%%{version}-vendor.tar.gz vendor
2323
Source1: %{name}-%{version}-vendor.tar.gz
@@ -79,6 +79,9 @@ exit 0
7979
%{install_sh}
8080

8181
%changelog
82+
* Thu Dec 08 2022 Vinayak Gupta <[email protected]> - 1.24.3-3
83+
- Update the vendor tarball with the corrected versions of the dependencies
84+
8285
* Tue Nov 01 2022 Olivia Crain <[email protected]> - 1.24.3-2
8386
- Bump release to rebuild with go 1.18.8
8487

@@ -107,4 +110,4 @@ exit 0
107110
- Initial CBL-Mariner import from Rancher (license: ASL 2.0).
108111

109112
* Mon Mar 2 2020 Erik Wilson <[email protected]> 0.1-1
110-
- Initial version
113+
- Initial version

0 commit comments

Comments
 (0)