On Thu, Jan 18, 2018 at 6:28 AM, Dusty Mabe <dusty(a)dustymabe.com> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Tomorrow we will attempt to release the 20180117 images.
These images contain the following ostree version/commits
from the Fedora-27-updates-20180117.0 updates run:
Version: 27.61
Commit(x86_64): 772ab185b0752b0d6bc8b2096d08955660d80ed95579e13e136e6a54e3559ca9
Commit(aarch64): 598626fd61dc6ed4b702159e50b6029ee70a527e855fce7d8e61a870b141f893
Commit(ppc64le): 16ce78ee689066f582dbfc0672dab1706051fefab496fcebd8109d58738eb8fe
The atomic host VM images are in the sub-directories under:
https://kojipkgs.fedoraproject.org/compose/twoweek/Fedora-Atomic-27-20180...
Tested qcow2 and raw images on aarch64 and ppc64le. They contain right
ostree commit and version number.
Basic tests and docker container runs fine. firewalld is available in
disabled mode.
Tested iso on aarch64 and ppc64le. They contain right ostree commit
and version number.
Basic tests and docker container runs fine. firewalld is available in
disabled mode.
> The AMIs are here:
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-northeast-1) ami-047b1d62 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-southeast-1) ami-df6a15a3 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-southeast-2) ami-a6b34cc4 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (eu-central-1) ami-88b926e7 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (eu-west-1) ami-9b0a93e2 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (sa-east-1) ami-0e6b2662 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-east-1) ami-6a98b410 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-west-1) ami-27313347 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-west-2) ami-ee952696 hvm
standard
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-northeast-1) ami-1846207e hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-southeast-1) ami-6666191a hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (ap-southeast-2) ami-bab14ed8 hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (eu-central-1) ami-76b62919 hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (eu-west-1) ami-a8069fd1 hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (sa-east-1) ami-006a276c hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-east-1) ami-6593bf1f hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-west-1) ami-29323049 hvm gp2
> Fedora-Atomic-27-20180117.1.x86_64 EC2 (us-west-2) ami-7c9f2c04 hvm gp2
>
> An example of the diff between this and the previous released version (for x86_64)
is:
>
> ostree diff commit old:
b5845ebd002b2ec829c937d68645400aa163e7265936b3e91734c6f33a510473
> ostree diff commit new:
772ab185b0752b0d6bc8b2096d08955660d80ed95579e13e136e6a54e3559ca9
> Upgraded:
> GeoIP-GeoLite-data 2017.10-1.fc27.noarch -> 2018.01-1.fc27.noarch
> bash 4.4.12-12.fc27.x86_64 -> 4.4.12-13.fc27.x86_64
> cockpit-bridge 158-1.fc27.x86_64 -> 159-1.fc27.x86_64
> cockpit-docker 158-1.fc27.x86_64 -> 159-1.fc27.x86_64
> cockpit-networkmanager 158-1.fc27.noarch -> 159-1.fc27.noarch
> cockpit-ostree 158-1.fc27.x86_64 -> 159-1.fc27.x86_64
> cockpit-system 158-1.fc27.noarch -> 159-1.fc27.noarch
> container-selinux 2:2.36-1.fc27.noarch -> 2:2.38-1.fc27.noarch
> dhcp-client 12:4.3.6-7.fc27.x86_64 -> 12:4.3.6-8.fc27.x86_64
> dhcp-common 12:4.3.6-7.fc27.noarch -> 12:4.3.6-8.fc27.noarch
> dhcp-libs 12:4.3.6-7.fc27.x86_64 -> 12:4.3.6-8.fc27.x86_64
> docker 2:1.13.1-42.git4402c09.fc27.x86_64 -> 2:1.13.1-44.git584d391.fc27.x86_64
> docker-common 2:1.13.1-42.git4402c09.fc27.x86_64 ->
2:1.13.1-44.git584d391.fc27.x86_64
> docker-rhel-push-plugin 2:1.13.1-42.git4402c09.fc27.x86_64 ->
2:1.13.1-44.git584d391.fc27.x86_64
> dracut 046-5.fc27.x86_64 -> 046-8.git20180105.fc27.x86_64
> dracut-config-generic 046-5.fc27.x86_64 -> 046-8.git20180105.fc27.x86_64
> dracut-network 046-5.fc27.x86_64 -> 046-8.git20180105.fc27.x86_64
> gdbm 1.13-3.fc27.x86_64 -> 1.14-1.fc27.x86_64
> gettext 0.19.8.1-11.fc27.x86_64 -> 0.19.8.1-12.fc27.x86_64
> gettext-libs 0.19.8.1-11.fc27.x86_64 -> 0.19.8.1-12.fc27.x86_64
> glibc 2.26-20.fc27.x86_64 -> 2.26-21.fc27.x86_64
> glibc-all-langpacks 2.26-20.fc27.x86_64 -> 2.26-21.fc27.x86_64
> glibc-common 2.26-20.fc27.x86_64 -> 2.26-21.fc27.x86_64
> glusterfs 3.12.4-1.fc27.x86_64 -> 3.12.5-1.fc27.x86_64
> glusterfs-client-xlators 3.12.4-1.fc27.x86_64 -> 3.12.5-1.fc27.x86_64
> glusterfs-fuse 3.12.4-1.fc27.x86_64 -> 3.12.5-1.fc27.x86_64
> glusterfs-libs 3.12.4-1.fc27.x86_64 -> 3.12.5-1.fc27.x86_64
> initscripts 9.78-1.fc27.x86_64 -> 9.79-1.fc27.x86_64
> iproute 4.13.0-1.fc27.x86_64 -> 4.14.1-4.fc27.x86_64
> iproute-tc 4.13.0-1.fc27.x86_64 -> 4.14.1-4.fc27.x86_64
> kernel 4.14.8-300.fc27.x86_64 -> 4.14.13-300.fc27.x86_64
> kernel-core 4.14.8-300.fc27.x86_64 -> 4.14.13-300.fc27.x86_64
> kernel-modules 4.14.8-300.fc27.x86_64 -> 4.14.13-300.fc27.x86_64
> kmod 24-3.fc27.x86_64 -> 25-1.fc27.x86_64
> kmod-libs 24-3.fc27.x86_64 -> 25-1.fc27.x86_64
> libcrypt-nss 2.26-20.fc27.x86_64 -> 2.26-21.fc27.x86_64
> libpkgconf 1.3.12-1.fc27.x86_64 -> 1.3.12-2.fc27.x86_64
> libseccomp 2.3.2-5.fc27.x86_64 -> 2.3.3-1.fc27.x86_64
> linux-firmware 20171215-81.git2451bb22.fc27.noarch ->
20171215-82.git2451bb22.fc27.noarch
> microcode_ctl 2:2.1-19.fc27.x86_64 -> 2:2.1-20.fc27.x86_64
> oci-register-machine 0-5.11.gitcd1e331.fc27.x86_64 ->
0-5.12.git3c01f0b.fc27.x86_64
> oci-systemd-hook 1:0.1.13-1.gitafe4b4a.fc27.x86_64 ->
1:0.1.15-1.git2d0b8a3.fc27.x86_64
> oci-umount 2:2.3.0-1.git51e7c50.fc27.x86_64 -> 2:2.3.2-1.git3025b19.fc27.x86_64
> os-prober 1.74-3.fc27.x86_64 -> 1.74-4.fc27.x86_64
> pcre 8.41-3.fc27.x86_64 -> 8.41-4.fc27.x86_64
> pcre2 10.30-3.fc27.x86_64 -> 10.30-5.fc27.x86_64
> pigz 2.3.4-3.fc27.x86_64 -> 2.4-1.fc27.x86_64
> pkgconf 1.3.12-1.fc27.x86_64 -> 1.3.12-2.fc27.x86_64
> pkgconf-m4 1.3.12-1.fc27.noarch -> 1.3.12-2.fc27.noarch
> pkgconf-pkg-config 1.3.12-1.fc27.x86_64 -> 1.3.12-2.fc27.x86_64
> publicsuffix-list-dafsa 20171028-1.fc27.noarch -> 20171228-1.fc27.noarch
> python2 2.7.14-4.fc27.x86_64 -> 2.7.14-5.fc27.x86_64
> python2-libs 2.7.14-4.fc27.x86_64 -> 2.7.14-5.fc27.x86_64
> runc 2:1.0.0-12.rc4.gitaea4f21.fc27.x86_64 ->
2:1.0.0-15.rc4.gite6516b3.fc27.x86_64
> selinux-policy 3.13.1-283.17.fc27.noarch -> 3.13.1-283.21.fc27.noarch
> selinux-policy-targeted 3.13.1-283.17.fc27.noarch -> 3.13.1-283.21.fc27.noarch
> vim-minimal 2:8.0.1386-1.fc27.x86_64 -> 2:8.0.1427-1.fc27.x86_64
> Added:
> ebtables-2.0.10-24.fc27.x86_64
> firewalld-0.4.4.5-3.fc27.noarch
> firewalld-filesystem-0.4.4.5-3.fc27.noarch
> ipset-6.32-1.fc27.x86_64
> ipset-libs-6.32-1.fc27.x86_64
> python3-firewall-0.4.4.5-3.fc27.noarch
>
> We have an updated kernel (the spectre patches are slowly working their way
> out [1]), and an updated docker with a security fix [2]. We also are *including*
> firewalld in the ostree now [3] but we are *not* enabling it by default. I'll
> post a follow up blog post on this topic in the next day or two.
>
> [1]
https://fedoramagazine.org/update-ongoing-meltdown-spectre-work/
> [2]
https://bugzilla.redhat.com/show_bug.cgi?id=1510351
> [3]
https://pagure.io/atomic-wg/issue/372
>
> Dusty
> -----BEGIN PGP SIGNATURE-----
>
> iQIzBAEBCAAdFiEEPb6zG5c6sV89tRYPMwLb1zlS5nEFAlpf8TcACgkQMwLb1zlS
> 5nFsQBAAj/5vpKnbkcuiMVYW+Ajn8Bs9pQMY4Zd+0or+MMzd0YSTky4e49W0TaFd
> jFRYxkSM8uPjdsIZuU/2rNfmQ19Zu2sO8eR9x134DSH2gqYtDmqSPGw9zbNMcW2B
> +tiMbFmFnPU8HtIP0QGcFXh/75ipmXiKbYZyEeul9W1BzAaC+Ww99UiB/TxiL0da
> oEFBNH+4E5r4jbYjRfk3PY9CaApZ5/Mu1paMGu7JpZSb5JXD65BFsoXXQKZ+BiD6
> 5qh2Y3jEvaaFPyDt4cuihC1wAdFKFVZp+Jm+UVXP601w5X6qtaJB4AiK6BwrMBbo
> pyzGszHOk5Ok9kIHXXOKBKWLFejh54Bn2jvTzLY/pFIonKnX82EpJKMoM8Fs+sBi
> 8PLwKW+CZ2hLzhPWAwpTO5phIPhJLszXVpiooSrFvMmXw+zjAUbvhlp+hXvhmBPp
> QK1esc95BgjujYF5xpzPfAyaP90suttdMwEqzVaaI5rx+ZQbr9ecO8NrcwXQnZE7
> 9GaMD9zUbjjrAxxAaQ0HDKtSgR4jRS7n6avs/YgKYx9FqMbbtEacUDWafHDzIp7Z
> yOWYGy1LpkvG4l1u6wXUh+WwCqYoY8ptpF1cDWbitUNk3qqMiKatR08IPASJPhqt
> hfSGstZ8VEgF298pStDrDqMklen1BEPAoVgsXMNjckLkLkAc0YY=
> =y436
> -----END PGP SIGNATURE-----
>