The following Fedora EPEL 8 Security updates need testing:
Age URL
11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-765ceaa306 clamav-0.102.3-1.el8
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-30aba92944 log4net-2.0.8-10.el8
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-2056b1c4a9 exim-4.93-3.el8
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-5660594875 python-markdown2-2.3.9-1.el8
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-c3fca161ee netdata-1.22.1-3.el8
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-38309f9f6f transmission-2.94-9.el8
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-06e970da9c knot-resolver-5.1.1-1.el8
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-383149ca50 perl-Email-MIME-1.949-1.el8 perl-Email-MIME-ContentType-1.024-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
OpenImageIO-2.1.15.0-2.el8
bashtop-0.9.3-1.el8
cros-guest-tools-1.0-0.33.20200524gitc91e2b4.el8
knot-2.9.5-1.el8
qbittorrent-4.2.5-2.el8
snapd-2.45-1.el8
snapd-glib-1.57-1.el8
Details about builds:
================================================================================
OpenImageIO-2.1.15.0-2.el8 (FEDORA-EPEL-2020-f586f0ae9d)
Library for reading and writing images
--------------------------------------------------------------------------------
Update Information:
Initial build for EPEL 8.
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 11 2020 Gwyn Ciesla <gwync(a)protonmail.com> - 2.1.15.0-2
- Rebuild for new LibRaw
* Mon May 11 2020 Richard Shaw <hobbes1069(a)gmail.com> - 2.1.15.0-1
- Update to 2.1.15.0.
- Adds support for libRaw 0.20, fixes RHBZ#1833450.
* Sat May 2 2020 Richard Shaw <hobbes1069(a)gmail.com> - 2.1.14.0-1
- Update to 2.1.14.0.
* Sun Apr 12 2020 Richard Shaw <hobbes1069(a)gmail.com> - 2.1.13.0-2
- Rebuild for funky depdendency problem in Rawhide/33.
* Thu Apr 2 2020 Richard Shaw <hobbes1069(a)gmail.com> - 2.1.13.0-1
- Update to 2.1.13.
* Tue Mar 3 2020 Richard Shaw <hobbes1069(a)gmail.com> - 2.1.12.0-1
- Update to 2.1.12.0.
--------------------------------------------------------------------------------
================================================================================
bashtop-0.9.3-1.el8 (FEDORA-EPEL-2020-413dd49879)
Linux resource monitor
--------------------------------------------------------------------------------
Update Information:
0.9.3 release
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Alessio <alciregi(a)fedoraproject.org> - 0.9.3-1
- 0.9.3 release
* Wed May 13 2020 Alessio <alciregi(a)fedoraproject.org> - 0.8.30-1
- 0.8.30 release
- Disable updates check
--------------------------------------------------------------------------------
================================================================================
cros-guest-tools-1.0-0.33.20200524gitc91e2b4.el8 (FEDORA-EPEL-2020-58fcfcad4d)
Chromium OS integration meta package
--------------------------------------------------------------------------------
Update Information:
Update to upstream master c91e2b4 and add xdg-utils as a recommended package.
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 24 2020 Jason Montleon jmontleo(a)redhat.com - 1.0-0.33.20200524gitc91e2b4
- Update to master c91e2b4
- Add xdg-utils to the recommended packages
--------------------------------------------------------------------------------
================================================================================
knot-2.9.5-1.el8 (FEDORA-EPEL-2020-659fddbebc)
High-performance authoritative DNS server
--------------------------------------------------------------------------------
Update Information:
- new upstream release 2.9.5
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Tomas Krizek <tomas.krizek(a)nic.cz> - 2.9.5-1
- new upstream release 2.9.5
--------------------------------------------------------------------------------
================================================================================
qbittorrent-4.2.5-2.el8 (FEDORA-EPEL-2020-c43f1768ca)
A Bittorrent Client
--------------------------------------------------------------------------------
Update Information:
Initial import to EPEL8 (#1784684)
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1784684 - Please add qbittorrent-nox to epel8
https://bugzilla.redhat.com/show_bug.cgi?id=1784684
--------------------------------------------------------------------------------
================================================================================
snapd-2.45-1.el8 (FEDORA-EPEL-2020-2944981ace)
A transactional software package manager
--------------------------------------------------------------------------------
Update Information:
Update to `snapd-2.45` and `snapd-glib-1.57`
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 20 2020 Maciek Borzecki <maciek.borzecki(a)gmail.com> - 2.45-1
- Release 2.45 to Fedora (RHBZ#1814552)
- Cherry pick zsh completion patch
- Cherry pick patch disabling fontconfig system cache sharing due to known
incompatibilities
- Drop sudoers config (RHBZ#1691996)
* Tue May 12 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.45
- o/devicestate: support doing system action reboots from recover
mode
- vendor: update to latest secboot
- tests: not fail when boot dir cannot be determined
- configcore: only reload journald if systemd is new enough
- cmd/snap-bootstrap/initramfs-mounts: append uuid to ubuntu-data
when decrypting
- tests/lib/prepare.sh: delete patching of the initrd
- cmd/snap: coldplug auto-import assertions from all removable
devices
- cmd/snap: fix the order of positional parameters in help output
- c/snap-bootstrap: port mount state mocking to the new style on
master
- cmd/snap-bootstrap/initramfs-mounts: add sudoers to dirs to copy
as well
- o/devicestate,cmd/snap-bootstrap: seal to recover mode cmdline,
unlock in recover mode initramfs
- progress: tweak multibyte label unit test data
- gadget: fix fallback device lookup for 'mbr' type structures
- progress: fix progress bar with multibyte duration units
- many: use /run/mnt/data over /run/mnt/ubuntu-data for uc20
- many: put the sealed keys in a directory on seed for tidiness
- cmd/snap-bootstrap: measure epoch and model before unlocking
encrypted data
- o/configstate: core config handler for persistent journal
- bootloader/uboot: use secondary ubootenv file boot.sel for uc20
- packaging: add "$TAGS" to dh_auto_test for debian packaging
- tests: ensure $cache_dir is actually available
- secboot,cmd/snap-bootstrap: add model to pcr protection profile
- devicestate: do not use snap-boostrap in devicestate to install
- tests: fix a typo in nested.sh helper
- devicestate: add support for cloud.cfg.d config from the gadget
- cmd/snap-bootstrap: cleanups, naming tweaks
- testutil: add NewDBusTestConn
- snap-bootstrap: lock access to sealed keys
- overlord/devicestate: preserve the current model inside ubuntu-
boot
- interfaces/apparmor: use differently templated policy for non-core
bases
- seccomp: add get_tls, io_pg* and *time64/*64 variants for existing
syscalls
- cmd/snap-bootstrap/initramfs-mounts: mount ubuntu-seed first,
other misc changes
- o/snapstate: tweak "waiting for restart" message
- boot: store model model and grade information in modeenv
- interfaces/firewall-control: allow -legacy and -nft for core20
- boot: enable makeBootable20RunMode for EnvRefExtractedKernel
bootloaders
- boot/bootstate20: add EnvRefExtractedKernelBootloader bootstate20
implementation
- daemon: fix error message from `snap remove-user foo` on classic
- overlord: have a variant of Mock that can take a state.State
- tests: 16.04 and 18.04 now have mediating pulseaudio (again)
- seed: clearer errors for missing essential snapd or core snap
- cmd/snap-bootstrap/initramfs-mounts: support
EnvRefExtractedKernelBootloader's
- gadget, cmd/snap-bootstrap: MBR schema support
- image: improve/adjust DownloadSnap doc comment
- asserts: introduce ModelGrade.Code
- tests: ignore user-12345 slice and service
- image,seed/seedwriter: support redirect channel aka default
tracks
- bootloader: use binary.Read/Write
- tests: uc20 nested suite part II
- tests/boot: refactor to make it easier for new
bootloaderKernelState20 impl
- interfaces/openvswitch: support use of ovs-appctl
- snap-bootstrap: copy auth data from real ubuntu-data in recovery
mode
- snap-bootstrap: seal and unseal encryption key using tpm
- tests: disable special-home-can-run-classic-snaps due to jenkins
repo issue
- packaging: fix build on Centos8 to support BUILDTAGS
- boot/bootstate20: small changes to bootloaderKernelState20
- cmd/snap: Implement a "snap routine file-access" command
- spread.yaml: switch back to latest/candidate for lxd snap
- boot/bootstate20: re-factor kernel methods to use new interface
for state
- spread.yaml,tests/many: use global env var for lxd channel
- boot/bootstate20: fix bug in try-kernel cleanup
- config: add system.store-certs.[a-zA-Z0-9] support
- secboot: key sealing also depends on secure boot enabled
- httputil: fix client timeout retry tests
- cmd/snap-update-ns: handle EBUSY when unlinking files
- cmd/snap/debug/boot-vars: add opts for setting dir and/or uc20
vars
- secboot: add tpm support helpers
- tests/lib/assertions/developer1-pi-uc20.model: use 20/edge for
kernel and gadget
- cmd/snap-bootstrap: switch to a 64-byte key for unlocking
- tests: preserve size for centos images on spread.yaml
- github: partition the github action workflows
- run-checks: use consistent "Checking ..." style messages
- bootloader: add efi pkg for reading efi variables
- data/systemd: do not run snapd.system-shutdown if finalrd is
available
- overlord: update tests to work with latest go
- cmd/snap: do not hide debug boot-vars on core
- cmd/snap-bootstrap: no error when not input devices are found
- snap-bootstrap: fix partition numbering in create-partitions
- httputil/client_test.go: add two TLS version tests
- tests: ignore user(a)12345.service hierarchy
- bootloader, gadget, cmd/snap-bootstrap: misc cosmetic things
- tests: rewrite timeserver-control test
- tests: fix racy pulseaudio tests
- many: fix loading apparmor profiles on Ubuntu 20.04 with ZFS
- tests: update snap-preseed --reset logic to accommodate for 2.44
change
- cmd/snap: don't wait for system key when stopping
- sandbox/cgroup: avoid making arrays we don't use
- osutil: mock proc/self/mountinfo properly everywhere
- selinux: export MockIsEnforcing; systemd: use in tests
- tests: add 32 bit machine to GH actions
- tests/session-tool: kill cron session, if any
- asserts: it should be possible to omit many snap-ids if allowed,
fix
- boot: cleanup more things, simplify code
- github: skip spread jobs when corresponding label is set
- dirs: don't depend on osutil anymore, mv apparmor vars to apparmor
pkg
- tests/session-tool: add session-tool --dump
- github: allow cached debian downloads to restore
- tests/session-tool: session ordering is non-deterministic
- tests: enable unit tests on debian-sid again
- github: move spread to self-hosted workers
- secboot: import secboot on ubuntu, provide dummy on !ubuntu
- overlord/devicestate: support for recover and run modes
- snap/naming: add validator for snap security tag
- interfaces: add case for rootWritableOverlay + NFS
- tests/main/uc20-create-partitions: tweaks, renames, switch to
20.04
- github: port CLA check to Github Actions
- interfaces/many: miscellaneous policy updates xliv
- configcore,tests: fix setting watchdog options on UC18/20
- tests/session-tool: collect information about services on startup
- tests/main/uc20-snap-recovery: unbreak, rename to uc20-create-
partitions
- state: add state.CopyState() helper
- tests/session-tool: stop anacron.service in prepare
- interfaces: don't use the owner modifier for files shared via
document portal
- systemd: move the doc comments to the interface so they are
visible
- cmd/snap-recovery-chooser: tweaks
- interfaces/docker-support: add overlayfs file access
- packaging: use debian/not-installed to ignore snap-preseed
- travis.yml: disable unit tests on travis
- store: start splitting store.go and store_test.go into subtopic
files
- tests/session-tool: stop cron/anacron from meddling
- github: disable fail-fast as spread cannot be interrupted
- github: move static checks and spread over
- tests: skip "/etc/machine-id" in "writablepaths" test
- snap-bootstrap: store encrypted partition recovery key
- httputil: increase testRetryStrategy max timelimit to 5s
- tests/session-tool: kill leaking closing session
- interfaces: allow raw access to USB printers
- tests/session-tool: reset failed session-tool units
- httputil: increase httpclient timeout in
TestRetryRequestTimeoutHandling
- usersession: extend timerange in TestExitOnIdle
- client: increase timeout in client tests to 100ms
- many: disentagle release and snapdenv from sandbox/*
- boot: simplify modeenv mocking to always write a modeenv
- snap-bootstrap: expand data partition on install
- o/configstate: add backlight option for core config
- cmd/snap-recovery-chooser: add recovery chooser
- features: enable robust mount ns updates
- snap: improve TestWaitRecovers test
- sandbox/cgroup: add ProcessPathInTrackingCgroup
- interfaces/policy: fix comment in recent new test
- tests: make session tool way more robust
- interfaces/seccomp: allow passing an address to setgroups
- o/configcore: introduce core config handlers (3/N)
- interfaces: updates to login-session-observe, network-manager and
modem-manager interfaces
- interfaces/policy/policy_test.go: add more tests'allow-
installation: false' and we grant based on interface attributes
- packaging: detect/disable broken seed in the postinst
- cmd/snap-confine/mount-support-nvidia.c: add libnvoptix as nvidia
library
- tests: remove google-tpm backend from spread.yaml
- tests: install dependencies with apt using --no-install-recommends
- usersession/userd: add zoommtg url support
- snap-bootstrap: fix disk layout sanity check
- snap: add `snap debug state --is-seeded` helper
- devicestate: generate warning if seeding fails
- config, features: move and rename config.GetFeatureFlag helper to
features.Flag
- boot, overlord/devicestate, daemon: implement requesting boot
into a given recovery system
- xdgopenproxy: forward requests to the desktop portal
- many: support immediate reboot
- store: search v2 tweaks
- tests: fix cross build tests when installing dependencies
- daemon: make POST /v2/systems/<label> root only
- tests/lib/prepare.sh: use only initrd from the kernel snap
- cmd/snap,seed: validate full seeds (UC 16/18)
- tests/main/user-session-env: stop the user session before deleting
the test-zsh user
- overlord/devicestate, daemon: record the seed current system was
installed from
- gadget: SystemDefaults helper function to convert system defaults
config into a flattened map suitable for FilesystemOnlyApply.
- many: comment or avoid cryptic snap-ids in tests
- tests: add LXD_CHANNEL environment
- store: support for search API v2
- .github: register a problem matcher to detect spread failures
- seed: add Info() method for seed.Snap
- github: always run the "Discard spread workers" step, even if the
job fails
- github: offload self-hosted workers
- cmd/snap: the model command needs just a client, no waitMixin
- github: combine tests into one workflow
- github: fix order of go get caches
- tests: adding more workers for ubuntu 20.04
- boot,overlord: rename operating mode to system mode
- config: add new Transaction.GetPristine{,Maybe}() function
- o/devicestate: rename readMaybe* to maybeRead*
- github: cache Debian dependencies for unit tests
- wrappers: respect pre-seeding in error path
- seed: validate UC20 seed system label
- client, daemon, overlord/devicestate: request system action API
and stubs
- asserts,o/devicestate: support model specified alternative serial-
authority
- many: introduce naming.WellKnownSnapID
- o/configcore: FilesystemOnlyApply method for early configuration
of core (1/N)
- github: run C unit tests
- github: run spread tests on PRs only
- interfaces/docker-support: make containerd abstract socket more
generic
- tests: cleanup security-private-tmp properly
- overlord/devicestate,boot: do not hold to the originally read
modeenv
- dirs: rm RunMnt; boot: add vars for early boot env layout;
sysconfig: take targetdir arg
- cmd/snap-bootstrap/initramfs-mounts/tests: use dirs.RunMnt over
s.runMnt
- tests: add regression test for MAAS refresh bug
- errtracker: add missing mocks
- github: apt-get update before installing build-deps
- github: don't fail-fast
- github: run spread via github actions
- boot,many: add modeenv.WriteTo, make Write take no args
- wrappers: fix timer schedules that are days only
- tests/main/snap-seccomp-syscalls: install gperf
- github: always checkout to snapcore/snapd
- github: add prototype workflow running unit tests
- many: improve comments, naming, a possible TODO
- client: use Assert when checking for error
- tests: ensure sockets target is ready in session agent spread
tests
- osutil: do not leave processes behind after the test run
- tests: update proxy-no-core to match latest CDN changes
- devicestate,sysconfig: support "cloud.cfg.d" in uc20 for grade:
dangerous
- cmd/snap-failure,tests: try to make snap-failure more robust
- many: fix packages having mistakenly their copyright as doc
- many: enumerate system seeds, return them on the /v2/systems API
endpoint
- randutil: don't consume kernel entropy at init, just mix more info
to try to avoid fleet collisions
- snap-bootstrap: add creationSupported predicate for partition
types
- tests: umount partitions which are not umounted after remount
gadget
- snap: run gofmt -s
- many: improve environment handling, fixing duplicate entries
- boot_test: add many boot robustness tests for UC20 kernel
MarkBootSuccessul and SetNextBoot
- overlord: remove unneeded overlord.MockPruneInterval() mocks
- interfaces/greengrass-support: fix typo
- overlord,timings,daemon: separate timings from overlord/state
- tests: enable nested on core20 and test current branch
- snap-bootstrap: remove created partitions on reinstall
- boot: apply Go 1.10 formatting
- apparmor: use rw for uuidd request to default and remove from
elsewhere
- packaging: add README.source for debian
- tests: cleanup various uc20 boot tests from previous PR
- devicestate: disable cloud-init by default on uc20
- run-checks: tweak formatting checks
- packaging,tests: ensure debian-sid builds without vendor/
- travis.yml: run unit tests with go/master as well* travis.yml: run
unit tests with go/master as well
- seed: make Brand() part of the Seed interface
- cmd/snap-update-ns: ignore EROFS from rmdir/unlink
- daemon: do a forceful server shutdown if we hit a deadline
- tests/many: don't use StartLimitInterval anymore, unify snapd-
failover variants, build snapd snap for UC16 tests
- snap-seccomp: robustness improvements
- run-tests: disable -v for go test to avoid spaming the logs
- snap: whitelist lzo as support compression for snap pack
- snap: tweak comment in Install() for overlayfs detection
- many: introduce snapdenv.Preseeding instead of release.PreseedMode
- client, daemon, overlord/devicestate: structures and stubs for
systems API
- o/devicestate: delay the creation of mark-seeded task until
asserts are loaded
- data/selinux, tests/main/selinux: cleanup tmpfs operations in the
policy, updates
- interfaces/greengrass-support: add new 1.9 access
- snap: do not hardlink on overlayfs
- boot,image: ARM kernel extract prepare image
- interfaces: make gpio robust against not-existing gpios in /sys
- cmd/snap-preseed: handle --reset flag
- many: introduce snapdenv to present common snapd env options
- interfaces/kubernetes-support: allow autobind to journald socket
- snap-seccomp: allow mprotect() to unblock the tests
- tests/lib/reset: workaround unicode dot in systemctl output
- interfaces/udisks2: also allow Introspection on
/org/freedesktop/UDisks/**
- snap: introduce Container.RandomAccessFile
- o/ifacestate, api: implementation of snap disconnect --forget
- cmd/snap: make the portal-info command search for the network-
status interface
- interfaces: work around apparmor_parser slowness affecting uio
- tests: fix/improve failing spread tests
- many: clean separation of bootenv mocking vs mock bootloader kinds
- tests: mock prune ticker in overlord tests to reduce wait times
- travis: disable arm64 again
- httputil: add support for extra snapd certs
- travis.yml: run unit tests on arm64 as well
- many: fix a pair of ineffectual assignments
- tests: add uc20 kernel snap upgrade managers test, fix
bootloadertest bugs
- o/snapstate: set base in SnapSetup on snap revert
- interfaces/{docker,kubernetes}-support: updates for lastest k8s
- cmd/snap-exec: add test case for LP bug 1860369
- interfaces: make the network-status interface implicit on
classic
- interfaces: power control interfaceIt is documented in the
kernel
- interfaces: miscellaneous policy updates
- cmd/snap: add a "snap routine portal-info" command
- usersession/userd: add "apt" to the white list of URL schemes
handled by xdg-open
- interfaces/desktop: allow access to system prompter interface
- devicestate: allow encryption regardless of grade
- tests: run ipv6 network-retry test too
- tests: test that after "remove-user" the system is unmanaged
- snap-confine: unconditionally add /dev/net/tun to the device
cgroup
- snapcraft.yaml: use sudo -E and remove workaround
- interfaces/audio_playback: Fix pulseaudio config access
- ovelord/snapstate: update only system wide fonts cache
- wrappers: import /etc/environment in all services
- interfaces/u2f: Add Titan USB-C key
- overlord, taskrunner: exit on task/ensure error when preseeding
- tests: add session-tool, a su / sudo replacement
- wrappers: add mount unit dependency for snapd services on core
devices
- tests: just remove user when the system is not managed on create-
user-2 test
- snap-preseed: support for preseeding of snapd and core18
- boot: misc UC20 changes
- tests: adding arch-linux execution
- packaging: revert "work around review-tools and snap-confine"
- netlink: fix panic on arm64 with the new rawsockstop codewith a
nil Timeval panics
- spread, data/selinux: add CentOS 8, update policy
- tests: updating checks to new test account for snapd-test snaps
- spread.yaml: mv opensuse 15.1 to unstable
- cmd/snap-bootstrap,seed: verify only in-play snaps
- tests: use ipv4 in retry-network to unblock failing master
- data/systemd: improve the description
- client: add "Resume" to DownloadOptions and new test
- tests: enable snapd-failover on uc20
- tests: add more debug output to the snapd-failure handling
- o/devicestate: unset recovery_system when done seeding
* Fri Apr 10 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.3
- tests: fix racy pulseaudio tests
- many: fix loading apparmor profiles on Ubuntu 20.04 with ZFS
- tests: update snap-preseed --reset logic
- tests: backport partition fixes
- cmd/snap: don't wait for system key when stopping
- interfaces/many: miscellaneous policy updates xliv
- tests/main/uc20-snap-recovery: use 20.04 system
- tests: skip "/etc/machine-id" in "writablepaths
- interfaces/docker-support: add overlays file access
* Thu Apr 2 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.2
- packaging: detect/disable broken seeds in the postinst
- cmd/snap,seed: validate full seeds (UC 16/18)
- snap: add `snap debug state --is-seeded` helper
- devicestate: generate warning if seeding fails
- store: support for search API v2
- cmd/snap-seccomp/syscalls: update the list of known syscalls
- snap/cmd: the model command needs just a client, no waitMixin
- tests: cleanup security-private-tmp properly
- wrappers: fix timer schedules that are days only
- tests: update proxy-no-core to match latest CDN changes
- cmd/snap-failure,tests: make snap-failure more robust
- tests, many: don't use StartLimitInterval anymore, unify snapd-
failover variants, build snapd snap for UC16 tests
* Sat Mar 21 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.1
- randutil: switch back to setting up seed with lower entropy data
- interfaces/greengrass-support: fix typo
- packaging,tests: ensure debian-sid builds without vendor/
- travis.yml: run unit tests with go/master as well
- cmd/snap-update-ns: ignore EROFS from rmdir/unlink
* Tue Mar 17 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44
- daemon: do a forceful serer shutdown if we hit a deadline
- snap: whitelist lzo as support compression for snap pack
- data/selinux: update policy to allow more ops
- interfaces/greengrass-support: add new 1.9 access
- snap: do not hardlink on overlayfs
- cmd/snap-preseed: handle --reset flag
- interfaces/kubernetes-support: allow autobind to journald socket
- snap-seccomp: allow mprotect() to unblock the tests
- tests/lib/reset: workaround unicode dot in systemctl output
- interfaces: work around apparmor_parser slowness affecting uio
- interfaces/udisks2: also allow Introspection on
/org/freedesktop/UDisks2/**
- tests: mock prune ticker in overlord tests to reduce wait times
- interfaces/{docker,kubernetes}-support: updates for lastest k8s
- interfaces: miscellaneous policy updates
- interfaces/audio_playback: Fix pulseaudio config access
- overlord: disable Test..AbortShortlyAfterStartOfOperation for 2.44
- ovelord/snapstate: update only system wide fonts cache
- wrappers: import /etc/environment in all services
- interfaces/u2f: Add Titan USB-C key
- overlord, taskrunner: exit on task/ensure error when preseeding
- overlord/snapstate/backend: update snapd services contents in unit
tests
- wrappers: add mount unit dependency for snapd services on core
devices
- Revert "tests: remove /tmp/snap.* left over by other tests"
- Revert "packaging: work around review-tools and snap-confine"
- netlink: fix panic on arm64 with the new rawsockstop code
- spread, data/selinux: add CentOS 8, update policy
- spread.yaml: mv opensuse tumbleweed to unstable too
- spread.yaml: mv opensuse 15.1 to unstable
- tests: use ipv4 in retry-network to unblock failing master
- data/systemd: improve the description
- tests/lib/prepare.sh: simplify, combine code paths
- tests/main/user-session-env: add test verifying environment
variables inside the user session
- spread.yaml: make qemu ubuntu-core-20-64 use ubuntu-20.04-64
- run-checks: SKIP_GMFMT really skips formatting checks
- tests: enable more tests for UC20/UC18
- tests: remove tmp dir for snap not-test-snapd-sh on security-
private-tmp test
- seed,cmd/snap-bootstrap: introduce seed.Snap.EssentialType,
simplify bootstrap code
- snapstate: do not restart in undoLinkSnap unless on first install
- cmd/snap-bootstrap: subcommand to detect UC chooser trigger
- cmd/snap-bootstrap/initramfs-mounts: mount the snapd snap in run-
mode too
- cmd/libsnap, tests: fix C unit tests failing as non-root
- cmd/snap-bootstrap: verify kernel snap is in modeenv before
mounting it
- tests: adding amazon linux to google backend
- cmd/snap-failure/snapd: rm snapd.socket, reset snapd.socket failed
status
- client: add support for "ResumeToken", "HeaderPeek" to download
- build: enable type: snapd
- tests: rm -rf /tmp/snap.* in restore
- cmd/snap-confine: deny snap-confine to load nss libs
- snapcraft.yaml: add comments, rename snapd part to snapd-deb
- boot: write current_kernels in bootstate20, makebootable
- packaging: work around review-tools and snap-confine
- tests: skipping interfaces-openvswitch on centos due to package is
not available
- packaging,snap-confine: stop being setgid root
- cmd/snap-confine: bring /var/lib/dhcp from host, if present
- store: rely on CommandFromSystemSnap to find xdelta3
- tests: bump sleep time of the new overlord tests
- cmd/snap-preseed: snapd version check for the target
- netlink: fix/support stopping goroutines reading netlink raw
sockets
- tests: reset PS1 before possibly interactive dash
- overlord, state: don't abort changes if spawn time before
StartOfOperationTime (2/2)
- snapcraft.yaml: add python3-apt, tzdata as build-deps for the
snapd snap
- tests: ask tar to speak English
- tests: using google storage when downloading ubuntu cloud images
from gce
- Coverity produces false positives for code like this:
- many: maybe restart & security backend options
- o/standby: add SNAPD_STANDBY_WAIT to control standby in
development
- snap: use the actual staging snap-id for snapd
- cmd/snap-bootstrap: create a new parser instance
- snapcraft.yaml: use build-base and adopt-info, rm builddeb
plugin
- tests: set StartLimitInterval in snapd failover test
- tests: disable archlinux system
- tests: add preseed test for classic
- many, tests: integrate all preseed bits and add spread tests
- daemon: support resuming downloads
- tests: use Filename() instead of filepath.Base(sn.MountFile())
- tests/core: add swapfiles test
- interfaces/cpu-control: allow to control cpufreq tunables
- interfaces: use commonInteface for desktopInterface
- interfaces/{desktop-legacy,unity7}: adjust for new ibus socket
location
- snap/info: add Filename
- bootloader: make uboot a RecoveryAwareBootloader
- gadget: skip update when mounted filesystem content is identical
- systemd: improve is-active check for 'failed' services
- boot: add current_kernels to modeenv
- o/devicestate: StartOfOperationTime helper for Prune (1/2)
- tests: detect LXD launching i386 containers
- tests: move main/ubuntu-core-* tests to core/ suite
- tests: remove snapd in ubuntu-core-snapd
- boot: enable base snap updates in bootstate20
- tests: Fix core revert channel after 2.43 has been released to
stable
- data/selinux: unify tabs/spaces
- o/ifacestate: move ResolveDisconnect to ifacestate
- spread: move centos to stable systems
- interfaces/opengl: allow datagrams to nvidia-driver
- httputil: add NoNetwork(err) helper, spread test and use in serial
acquire
- store: detect if server does not support http range headers
- test/lib/user: add helper lib for doing things for and as a user
- overlord/snapstate, wrappers: undo of snapd on core
- tests/main/interfaces-pulseaudio: use custom pulseaudio script,
set kill timeout
- store: add support for resume in DownloadStream
- cmd/snap: implement 'snap remove-user'
- overlord/devicestate: fix preseed unit tests on systems not using
/snap
- tests/main/static: ldd in glibc 2.31 logs to stderr now
- run-checks, travis: allow skipping spread jobs by adding a label
- tests: add new backend which includes images with tpm support
- boot: use constants for boot status values
- tests: add "core" suite for UC specific tests
- tests/lib/prepare: use a local copy of uc20 initramfs skeleton
- tests: retry mounting the udisk2 device due to timing issue
- usersession/client: add a client library for the user session
agent
- o/devicestate: Handle preseed mode in the firstboot mode (core16
only for now).
- boot: add TryBase and BaseStatus to modeenv; use in snap-bootstrap
- cmd/snap-confine: detect base transitions on core16
- boot: don't use "kernel" from the modeenv anymore
- interfaces: add uio interface
- tests: repack the initramfs + kernel snap for UC20 spread tests
- interfaces/greengrass-support: add /dev/null ->
/proc/latency_stats mount
- httputil: remove workaround for redirect handling in go1.7
- httputil: remove go1.6 transport workaround
- snap: add `snap pack --compression=<comp>` options
- tests/lib/prepare: fix hardcoded loopback device names for UC
images
- timeutil: add a unit test case for trivial schedule
- randutil,o/snapstate,-mkauthors.sh: follow ups to randutil
introduction
- dirs: variable with distros using alternate snap mount
- many,randutil: centralize and streamline our random value
generation
- tests/lib/prepare-restore: Revert "Continue on errors updating or
installing dependencies"
- daemon: Allow clients to call /v2/logout via Polkit
- dirs: manjaro-arm is like manjaro
- data, packaging: Add sudoers snippet to allow snaps to be run with
sudo
- daemon, store: better expose single action errors
- tests: switch mount-ns test to differential data set
- snapstate: refactor things to add the re-refresh task last
- daemon: drop support for the DELETE method
- client: move to /v2/users; implement RemoveUser
- boot: enable UC20 kernel extraction and bootState20 handling
- interfaces/policy: enforce plug-names/slot-names constraints
- asserts: parse plug-names/slot-names constraints
- daemon: make users result more consistent
- cmd/snap-confine,tests: support x.y.z nvidia version
- dirs: fixlet for XdgRuntimeDirGlob
- boot: add bootloader options to coreKernel
- o/auth,daemon: do not remove unknown user
- tests: tweak and enable tests on ubuntu 20.04
- daemon: implement user removal
- cmd/snap-confine: allow snap-confine to link to libpcre2
- interfaces/builtin: Allow NotificationReplied signal on
org.freedesktop.Notifications
- overlord/auth: add RemoveUserByName
- client: move user-related things to their own files
- boot: tweak kernel cmdline helper docstring
- osutil: implement deluser
- gadget: skip update when raw structure content is unchanged
- boot, cmd/snap, cmd/snap-bootstrap: move run mode and system label
detection to boot
- tests: fix revisions leaking from snapd-refresh test
- daemon: refactor create-user to a user action & hide behind a flag
- osutil/tests: check there are no leftover symlinks with
AtomicSymlink
- grub: support atomically renaming kernel symlinks
- osutil: add helpers for creating symlinks and renaming in an
atomic manner
- tests: add marker tag for core 20 test failure
- tests: fix gadget-update-pc test leaking snaps
- tests: remove revision leaking from ubuntu-core-refresh
- tests: remove revision leaking from remodel-kernel
- tests: disable system-usernames test on core20
- travis, tests, run-checks: skip nakedret
- tests: run `uc20-snap-recovery-encrypt` test on 20.04-64 as well
- tests: update mount-ns test tables
- snap: disable auto-import in uc20 install-mode
- tests: add a command-chain service test
- tests: use test-snapd-upower instead of upower
- data/selinux: workaround incorrect fonts cache labeling on RHEL7
- spread.yaml: fix ubuntu 19.10 and 20.04 names
- debian: check embedded keys for snap-{bootstrap,preseed} too
- interfaces/apparmor: fix doc-comments, unnecessary code
- o/ifacestate,o/devicestatate: merge gadget-connect logic into
auto-connect
- bootloader: add ExtractedRunKernelImageBootloader interface,
implement in grub
- tests: add spread test for hook permissions
- cmd/snap-bootstrap: check device size before boostrapping and
produce a meaningful error
- cmd/snap: add ability to register "snap routine" commands
- tests: add a test demonstrating that snaps can't access the
session agent socket
- api: don't return connections referring to non-existing
plugs/slots
- interfaces: refactor path() from raw-volume into utils with
comments for old
- gitignore: ignore snap files
- tests: skip interfaces-network-manager on arm devices
- o/devicestate: do not create perfTimings if not needed inside
ensureSeed/Operational
- tests: add ubuntu 20.04 to the tests execution and remove
tumbleweed from unstable
- usersession: add systemd user instance service control to user
session agent
- cmd/snap: print full channel in 'snap list', 'snap info'
- tests: remove execution of ubuntu 19.04 from google backend
- cmd/snap-boostrap: add mocking for fakeroot
- tests/core18/snapd-failover: collect more debug info
- many: run black formatter on all python files
- overlord: increase settle timeout for slow machines
- httputil: use shorter timeout in TestRetryRequestTimeoutHandling
- store, o/snapstate: send default-tracks header, use
RedirectChannel
- overlord/standby: fix possible deadlock in standby test
- cmd/snap-discard-ns: fix pattern for .info files
- boot: add HasModeenv to Device
- devicestate: do not allow remodel between core20 models
- bootloader,snap: misc tweaks
- store, overlord/snapstate, etc: SnapAction now returns a []���Result
- snap-bootstrap: create encrypted partition
- snap: remove "host" output from `snap version`
- tests: use snap remove --purge flag in most of the spread tests
- data/selinux, test/main/selinux-clean: update the test to cover
more scenarios
- many: drop NameAndRevision, use snap.PlaceInfo instead
- boot: split MakeBootable tests into their own file
- travis-ci: add go import path
- boot: split MakeBootable implementations into their own file
- tests: enable a lot of the tests of main on uc20
- packaging, tests: stop services in prerm
- tests: enable regression suite on core20
- overlord/snapstate: improve snapd snap backend link unit tests
- boot: implement SetNextBoot in terms of bootState.setNext
- wrappers: write and undo snapd services on core
- boot,o/devicestate: refactor MarkBootSuccessful over bootState
- snap-bootstrap: mount the correct snapd snap to /run/mnt/snapd
- snap-bootstrap: refactor partition creation
- tests: use new snapd.spread-tests-run-mode-tweaks.service unit
- tests: add core20 tests
- boot,o/snapstate: SetNextBoot/LinkSnap return whether to reboot,
use the information
- tests/main/snap-sign: add test for non-stdin signing
- snap-bootstrap: trigger udev after filesystem creation
- boot,overlord: introduce internal abstraction bootState and use it
for InUse/GetCurrentBoot
- overlord/snapstate: tracks are now sticky
- cmd: sign: add filename param
- tests: remove "test-snapd-tools" in smoke/sandbox on restore
- cmd/snap, daemon: stop over-normalising channels
- tests: fix classic-ubuntu-core-transition-two-cores after refactor
of MATCH -v
- packaging: ship var/lib/snapd/desktop/applications in the pkg
- spread: drop copr repo with F30 build dependencies
- tests: use test-snapd-sh snap instead of test-snapd-tools - Part 3
- tests: fix partition creation test
- tests: unify/rename services-related spread tests to start with
services- prefix
- test: extract code that modifies "writable" for test prep
- systemd: handle preseed mode
- snap-bootstrap: read only stdout when parsing the sfdisk json
- interfaces/browser-support: add more product/vendor paths
- boot: write compat UC16 bootvars in makeBootable20RunMode
- devicestate: avoid adding mockModel to deviceMgrInstallModeSuite
- devicestate: request reboot after successful doSetupRunSystem()
- snapd.core-fixup.sh: do not run on UC20 at all
- tests: unmount automounted snap-bootstrap devices
- devicestate: run boot.MakeBootable in doSetupRunSystem
- boot: copy kernel/base to data partition in makeBootable20RunMode
- tests: also check nested lxd container
- run-checks: complain about MATCH -v
- boot: always return the trivial boot participant in ephemeral mode
- o/devicestate,o/snapstate: move the gadget.yaml checkdrive-by: use
gadget.ReadInfoFromSnapFile in checkGadgetRemodelCompatible
- snap-bootstrap: append new partitions
- snap-bootstrap: mount filesystems after creation
- snapstate: do not try to detect rollback in ephemeral modes
- snap-bootstrap: trigger udev for new partitions
- cmd/snap-bootstrap: xxx todos about kernel cross-checks
- tests: avoid mask rsyslog service in case is not enabled on the
system
- tests: fix use of MATCH -v
- cmd/snap-preseed: update help strings
- cmd/snap-bootstrap: actually parse snapd_recovery_system label
- bootstrap: reduce runmode mounts from 5 to 2 steps.
- lkenv.go: adjust for new location of include file
- snap: improve squashfs.ReadFile() error
- systemd: fix uc20 shutdown
- boot: write modeenv when creating the run mode
- boot,image: add skeleton boot.makeBootable20RunMode
- cmd/snap-preseed: add snap-preseed executable
- overlord,boot: follow ups to #7889 and #7899
- interfaces/wayland: Add access to Xwayland's shm files
- o/hookstate/ctlcmd: fix command name in snapctl -h
- daemon,snap: remove screenshot deprecation notice
- overlord,o/snapstate: make sure we never leave config behind
- many: pass consistently boot.Device state to boot methods
- run-checks: check multiline string blocks in
restore/prepare/execute sections of spread tests
- intrefaces: login-session-control - added missing dbus commands
- tests/main/parallel-install-remove-after: parallel installs should
not break removal
- overlord/snapstate: tweak assumes error hint
- overlord: replace DeviceContext.OldModel with GroundContext
- devicestate: use httputil.ShouldRetryError() in
prepareSerialRequest
- tests: replace "test-snapd-base-bare" with real "bare" base snap
- many: pass a Model to the gadget info reading functions
- snapstate: relax gadget constraints in ConfigDefaults Et al.
- devicestate: only run ensureBootOk() in "run" mode
- tests/many: quiet lxc launching, file pushing
- tests: disable apt-hooks test until it can be properly fixed
- tests: 16.04 and 18.04 now have mediating pulseaudio
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1811793 - snapd-glib-1.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1811793
[ 2 ] Bug #1814552 - snapd-2.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1814552
--------------------------------------------------------------------------------
================================================================================
snapd-glib-1.57-1.el8 (FEDORA-EPEL-2020-2944981ace)
Library providing a GLib interface to snapd
--------------------------------------------------------------------------------
Update Information:
Update to `snapd-2.45` and `snapd-glib-1.57`
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Neal Gompa <ngompa13(a)gmail.com> - 1.57-1
- Update to 1.57
- Add snapd_interface_make_label
- Add support for new snap types: "core", "base" and "snapd"
- Change way GTK documentation is generated to avoid a Meson bug
- Fix leak in markdown parser
- Fix leak in logout code
- Make build reproducible by fixing comment in generated file
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1811793 - snapd-glib-1.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1811793
[ 2 ] Bug #1814552 - snapd-2.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1814552
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
650 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d condor-8.6.11-1.el7
392 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-c499781e80 python-gnupg-0.4.4-1.el7
390 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-bc0182548b bubblewrap-0.3.3-2.el7
99 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fa8a2e97c6 python-waitress-1.4.3-1.el7
39 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19d171a465 python34-3.4.10-5.el7
11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff94ccbdec openssl11-1.1.1c-2.el7
11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-624f38e579 qbittorrent-3.3.16-2.el7
11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-235a51a239 clamav-0.102.3-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ae83e43288 log4net-2.0.8-10.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-134c471656 json-c12-0.12.1-4.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-567eda5296 exim-4.93-3.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff11142989 netdata-1.22.1-3.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-e7814b7723 transmission-2.94-9.el7
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19de895038 knot-resolver-5.1.1-1.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ed6bc3c8d4 golang-1.13.11-1.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-05b9f2eac5 sympa-6.2.56-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
knot-2.9.5-1.el7
python-wxpython4-4.0.7-6.el7
python3-sip-4.19.22-1.el7
smoldyn-2.61-3.el7
snapd-2.45-1.el7
snapd-glib-1.57-1.el7
zstd-1.4.5-3.el7
Details about builds:
================================================================================
knot-2.9.5-1.el7 (FEDORA-EPEL-2020-54893683b6)
High-performance authoritative DNS server
--------------------------------------------------------------------------------
Update Information:
- new upstream release 2.9.5
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Tomas Krizek <tomas.krizek(a)nic.cz> - 2.9.5-1
- new upstream release 2.9.5
--------------------------------------------------------------------------------
================================================================================
python-wxpython4-4.0.7-6.el7 (FEDORA-EPEL-2020-cadeec41c2)
New implementation of wxPython, a GUI toolkit for Python
--------------------------------------------------------------------------------
Update Information:
fix a crash wxPython.
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Scott Talbert <swt(a)techie.net> - 4.0.7-6
- Rebuild with sip 4.19.22 to fix ArtProvider crash (for real)
* Fri May 22 2020 Scott Talbert <swt(a)techie.net> - 4.0.7-5
- Rebuild with sip 4.19.22 to fix ArtProvider crash
--------------------------------------------------------------------------------
================================================================================
python3-sip-4.19.22-1.el7 (FEDORA-EPEL-2020-cadeec41c2)
SIP - Python/C++ Bindings Generator
--------------------------------------------------------------------------------
Update Information:
fix a crash wxPython.
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 18 2020 Scott Talbert <swt(a)techie.net> - 4.19.22-1
- Update to new upstream release 4.19.22
--------------------------------------------------------------------------------
================================================================================
smoldyn-2.61-3.el7 (FEDORA-EPEL-2020-1f449e51e6)
A particle-based spatial stochastic simulator
--------------------------------------------------------------------------------
Update Information:
- Release 2.61 - Patched to use Boost169
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Antonio Trande <sagitter(a)fedoraproject.org> - 2.61-3
- Fix patch for EPEL7
* Mon May 25 2020 Antonio Trande <sagitter(a)fedoraproject.org> - 2.61-2
- Patched for using Boost169 on EPEL7
* Sun May 24 2020 Antonio Trande <sagitter(a)fedoraproject.org> - 2.61-1
- Release 2.61
* Thu Jan 30 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.58-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Tue Sep 17 2019 Gwyn Ciesla <gwync(a)protonmail.com> - 2.58-3
- Rebuilt for new freeglut
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.58-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
snapd-2.45-1.el7 (FEDORA-EPEL-2020-6e69f4cf75)
A transactional software package manager
--------------------------------------------------------------------------------
Update Information:
Update to `snapd-2.45` and `snapd-glib-1.57`
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 20 2020 Maciek Borzecki <maciek.borzecki(a)gmail.com> - 2.45-1
- Release 2.45 to Fedora (RHBZ#1814552)
- Cherry pick zsh completion patch
- Cherry pick patch disabling fontconfig system cache sharing due to known
incompatibilities
- Drop sudoers config (RHBZ#1691996)
* Tue May 12 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.45
- o/devicestate: support doing system action reboots from recover
mode
- vendor: update to latest secboot
- tests: not fail when boot dir cannot be determined
- configcore: only reload journald if systemd is new enough
- cmd/snap-bootstrap/initramfs-mounts: append uuid to ubuntu-data
when decrypting
- tests/lib/prepare.sh: delete patching of the initrd
- cmd/snap: coldplug auto-import assertions from all removable
devices
- cmd/snap: fix the order of positional parameters in help output
- c/snap-bootstrap: port mount state mocking to the new style on
master
- cmd/snap-bootstrap/initramfs-mounts: add sudoers to dirs to copy
as well
- o/devicestate,cmd/snap-bootstrap: seal to recover mode cmdline,
unlock in recover mode initramfs
- progress: tweak multibyte label unit test data
- gadget: fix fallback device lookup for 'mbr' type structures
- progress: fix progress bar with multibyte duration units
- many: use /run/mnt/data over /run/mnt/ubuntu-data for uc20
- many: put the sealed keys in a directory on seed for tidiness
- cmd/snap-bootstrap: measure epoch and model before unlocking
encrypted data
- o/configstate: core config handler for persistent journal
- bootloader/uboot: use secondary ubootenv file boot.sel for uc20
- packaging: add "$TAGS" to dh_auto_test for debian packaging
- tests: ensure $cache_dir is actually available
- secboot,cmd/snap-bootstrap: add model to pcr protection profile
- devicestate: do not use snap-boostrap in devicestate to install
- tests: fix a typo in nested.sh helper
- devicestate: add support for cloud.cfg.d config from the gadget
- cmd/snap-bootstrap: cleanups, naming tweaks
- testutil: add NewDBusTestConn
- snap-bootstrap: lock access to sealed keys
- overlord/devicestate: preserve the current model inside ubuntu-
boot
- interfaces/apparmor: use differently templated policy for non-core
bases
- seccomp: add get_tls, io_pg* and *time64/*64 variants for existing
syscalls
- cmd/snap-bootstrap/initramfs-mounts: mount ubuntu-seed first,
other misc changes
- o/snapstate: tweak "waiting for restart" message
- boot: store model model and grade information in modeenv
- interfaces/firewall-control: allow -legacy and -nft for core20
- boot: enable makeBootable20RunMode for EnvRefExtractedKernel
bootloaders
- boot/bootstate20: add EnvRefExtractedKernelBootloader bootstate20
implementation
- daemon: fix error message from `snap remove-user foo` on classic
- overlord: have a variant of Mock that can take a state.State
- tests: 16.04 and 18.04 now have mediating pulseaudio (again)
- seed: clearer errors for missing essential snapd or core snap
- cmd/snap-bootstrap/initramfs-mounts: support
EnvRefExtractedKernelBootloader's
- gadget, cmd/snap-bootstrap: MBR schema support
- image: improve/adjust DownloadSnap doc comment
- asserts: introduce ModelGrade.Code
- tests: ignore user-12345 slice and service
- image,seed/seedwriter: support redirect channel aka default
tracks
- bootloader: use binary.Read/Write
- tests: uc20 nested suite part II
- tests/boot: refactor to make it easier for new
bootloaderKernelState20 impl
- interfaces/openvswitch: support use of ovs-appctl
- snap-bootstrap: copy auth data from real ubuntu-data in recovery
mode
- snap-bootstrap: seal and unseal encryption key using tpm
- tests: disable special-home-can-run-classic-snaps due to jenkins
repo issue
- packaging: fix build on Centos8 to support BUILDTAGS
- boot/bootstate20: small changes to bootloaderKernelState20
- cmd/snap: Implement a "snap routine file-access" command
- spread.yaml: switch back to latest/candidate for lxd snap
- boot/bootstate20: re-factor kernel methods to use new interface
for state
- spread.yaml,tests/many: use global env var for lxd channel
- boot/bootstate20: fix bug in try-kernel cleanup
- config: add system.store-certs.[a-zA-Z0-9] support
- secboot: key sealing also depends on secure boot enabled
- httputil: fix client timeout retry tests
- cmd/snap-update-ns: handle EBUSY when unlinking files
- cmd/snap/debug/boot-vars: add opts for setting dir and/or uc20
vars
- secboot: add tpm support helpers
- tests/lib/assertions/developer1-pi-uc20.model: use 20/edge for
kernel and gadget
- cmd/snap-bootstrap: switch to a 64-byte key for unlocking
- tests: preserve size for centos images on spread.yaml
- github: partition the github action workflows
- run-checks: use consistent "Checking ..." style messages
- bootloader: add efi pkg for reading efi variables
- data/systemd: do not run snapd.system-shutdown if finalrd is
available
- overlord: update tests to work with latest go
- cmd/snap: do not hide debug boot-vars on core
- cmd/snap-bootstrap: no error when not input devices are found
- snap-bootstrap: fix partition numbering in create-partitions
- httputil/client_test.go: add two TLS version tests
- tests: ignore user(a)12345.service hierarchy
- bootloader, gadget, cmd/snap-bootstrap: misc cosmetic things
- tests: rewrite timeserver-control test
- tests: fix racy pulseaudio tests
- many: fix loading apparmor profiles on Ubuntu 20.04 with ZFS
- tests: update snap-preseed --reset logic to accommodate for 2.44
change
- cmd/snap: don't wait for system key when stopping
- sandbox/cgroup: avoid making arrays we don't use
- osutil: mock proc/self/mountinfo properly everywhere
- selinux: export MockIsEnforcing; systemd: use in tests
- tests: add 32 bit machine to GH actions
- tests/session-tool: kill cron session, if any
- asserts: it should be possible to omit many snap-ids if allowed,
fix
- boot: cleanup more things, simplify code
- github: skip spread jobs when corresponding label is set
- dirs: don't depend on osutil anymore, mv apparmor vars to apparmor
pkg
- tests/session-tool: add session-tool --dump
- github: allow cached debian downloads to restore
- tests/session-tool: session ordering is non-deterministic
- tests: enable unit tests on debian-sid again
- github: move spread to self-hosted workers
- secboot: import secboot on ubuntu, provide dummy on !ubuntu
- overlord/devicestate: support for recover and run modes
- snap/naming: add validator for snap security tag
- interfaces: add case for rootWritableOverlay + NFS
- tests/main/uc20-create-partitions: tweaks, renames, switch to
20.04
- github: port CLA check to Github Actions
- interfaces/many: miscellaneous policy updates xliv
- configcore,tests: fix setting watchdog options on UC18/20
- tests/session-tool: collect information about services on startup
- tests/main/uc20-snap-recovery: unbreak, rename to uc20-create-
partitions
- state: add state.CopyState() helper
- tests/session-tool: stop anacron.service in prepare
- interfaces: don't use the owner modifier for files shared via
document portal
- systemd: move the doc comments to the interface so they are
visible
- cmd/snap-recovery-chooser: tweaks
- interfaces/docker-support: add overlayfs file access
- packaging: use debian/not-installed to ignore snap-preseed
- travis.yml: disable unit tests on travis
- store: start splitting store.go and store_test.go into subtopic
files
- tests/session-tool: stop cron/anacron from meddling
- github: disable fail-fast as spread cannot be interrupted
- github: move static checks and spread over
- tests: skip "/etc/machine-id" in "writablepaths" test
- snap-bootstrap: store encrypted partition recovery key
- httputil: increase testRetryStrategy max timelimit to 5s
- tests/session-tool: kill leaking closing session
- interfaces: allow raw access to USB printers
- tests/session-tool: reset failed session-tool units
- httputil: increase httpclient timeout in
TestRetryRequestTimeoutHandling
- usersession: extend timerange in TestExitOnIdle
- client: increase timeout in client tests to 100ms
- many: disentagle release and snapdenv from sandbox/*
- boot: simplify modeenv mocking to always write a modeenv
- snap-bootstrap: expand data partition on install
- o/configstate: add backlight option for core config
- cmd/snap-recovery-chooser: add recovery chooser
- features: enable robust mount ns updates
- snap: improve TestWaitRecovers test
- sandbox/cgroup: add ProcessPathInTrackingCgroup
- interfaces/policy: fix comment in recent new test
- tests: make session tool way more robust
- interfaces/seccomp: allow passing an address to setgroups
- o/configcore: introduce core config handlers (3/N)
- interfaces: updates to login-session-observe, network-manager and
modem-manager interfaces
- interfaces/policy/policy_test.go: add more tests'allow-
installation: false' and we grant based on interface attributes
- packaging: detect/disable broken seed in the postinst
- cmd/snap-confine/mount-support-nvidia.c: add libnvoptix as nvidia
library
- tests: remove google-tpm backend from spread.yaml
- tests: install dependencies with apt using --no-install-recommends
- usersession/userd: add zoommtg url support
- snap-bootstrap: fix disk layout sanity check
- snap: add `snap debug state --is-seeded` helper
- devicestate: generate warning if seeding fails
- config, features: move and rename config.GetFeatureFlag helper to
features.Flag
- boot, overlord/devicestate, daemon: implement requesting boot
into a given recovery system
- xdgopenproxy: forward requests to the desktop portal
- many: support immediate reboot
- store: search v2 tweaks
- tests: fix cross build tests when installing dependencies
- daemon: make POST /v2/systems/<label> root only
- tests/lib/prepare.sh: use only initrd from the kernel snap
- cmd/snap,seed: validate full seeds (UC 16/18)
- tests/main/user-session-env: stop the user session before deleting
the test-zsh user
- overlord/devicestate, daemon: record the seed current system was
installed from
- gadget: SystemDefaults helper function to convert system defaults
config into a flattened map suitable for FilesystemOnlyApply.
- many: comment or avoid cryptic snap-ids in tests
- tests: add LXD_CHANNEL environment
- store: support for search API v2
- .github: register a problem matcher to detect spread failures
- seed: add Info() method for seed.Snap
- github: always run the "Discard spread workers" step, even if the
job fails
- github: offload self-hosted workers
- cmd/snap: the model command needs just a client, no waitMixin
- github: combine tests into one workflow
- github: fix order of go get caches
- tests: adding more workers for ubuntu 20.04
- boot,overlord: rename operating mode to system mode
- config: add new Transaction.GetPristine{,Maybe}() function
- o/devicestate: rename readMaybe* to maybeRead*
- github: cache Debian dependencies for unit tests
- wrappers: respect pre-seeding in error path
- seed: validate UC20 seed system label
- client, daemon, overlord/devicestate: request system action API
and stubs
- asserts,o/devicestate: support model specified alternative serial-
authority
- many: introduce naming.WellKnownSnapID
- o/configcore: FilesystemOnlyApply method for early configuration
of core (1/N)
- github: run C unit tests
- github: run spread tests on PRs only
- interfaces/docker-support: make containerd abstract socket more
generic
- tests: cleanup security-private-tmp properly
- overlord/devicestate,boot: do not hold to the originally read
modeenv
- dirs: rm RunMnt; boot: add vars for early boot env layout;
sysconfig: take targetdir arg
- cmd/snap-bootstrap/initramfs-mounts/tests: use dirs.RunMnt over
s.runMnt
- tests: add regression test for MAAS refresh bug
- errtracker: add missing mocks
- github: apt-get update before installing build-deps
- github: don't fail-fast
- github: run spread via github actions
- boot,many: add modeenv.WriteTo, make Write take no args
- wrappers: fix timer schedules that are days only
- tests/main/snap-seccomp-syscalls: install gperf
- github: always checkout to snapcore/snapd
- github: add prototype workflow running unit tests
- many: improve comments, naming, a possible TODO
- client: use Assert when checking for error
- tests: ensure sockets target is ready in session agent spread
tests
- osutil: do not leave processes behind after the test run
- tests: update proxy-no-core to match latest CDN changes
- devicestate,sysconfig: support "cloud.cfg.d" in uc20 for grade:
dangerous
- cmd/snap-failure,tests: try to make snap-failure more robust
- many: fix packages having mistakenly their copyright as doc
- many: enumerate system seeds, return them on the /v2/systems API
endpoint
- randutil: don't consume kernel entropy at init, just mix more info
to try to avoid fleet collisions
- snap-bootstrap: add creationSupported predicate for partition
types
- tests: umount partitions which are not umounted after remount
gadget
- snap: run gofmt -s
- many: improve environment handling, fixing duplicate entries
- boot_test: add many boot robustness tests for UC20 kernel
MarkBootSuccessul and SetNextBoot
- overlord: remove unneeded overlord.MockPruneInterval() mocks
- interfaces/greengrass-support: fix typo
- overlord,timings,daemon: separate timings from overlord/state
- tests: enable nested on core20 and test current branch
- snap-bootstrap: remove created partitions on reinstall
- boot: apply Go 1.10 formatting
- apparmor: use rw for uuidd request to default and remove from
elsewhere
- packaging: add README.source for debian
- tests: cleanup various uc20 boot tests from previous PR
- devicestate: disable cloud-init by default on uc20
- run-checks: tweak formatting checks
- packaging,tests: ensure debian-sid builds without vendor/
- travis.yml: run unit tests with go/master as well* travis.yml: run
unit tests with go/master as well
- seed: make Brand() part of the Seed interface
- cmd/snap-update-ns: ignore EROFS from rmdir/unlink
- daemon: do a forceful server shutdown if we hit a deadline
- tests/many: don't use StartLimitInterval anymore, unify snapd-
failover variants, build snapd snap for UC16 tests
- snap-seccomp: robustness improvements
- run-tests: disable -v for go test to avoid spaming the logs
- snap: whitelist lzo as support compression for snap pack
- snap: tweak comment in Install() for overlayfs detection
- many: introduce snapdenv.Preseeding instead of release.PreseedMode
- client, daemon, overlord/devicestate: structures and stubs for
systems API
- o/devicestate: delay the creation of mark-seeded task until
asserts are loaded
- data/selinux, tests/main/selinux: cleanup tmpfs operations in the
policy, updates
- interfaces/greengrass-support: add new 1.9 access
- snap: do not hardlink on overlayfs
- boot,image: ARM kernel extract prepare image
- interfaces: make gpio robust against not-existing gpios in /sys
- cmd/snap-preseed: handle --reset flag
- many: introduce snapdenv to present common snapd env options
- interfaces/kubernetes-support: allow autobind to journald socket
- snap-seccomp: allow mprotect() to unblock the tests
- tests/lib/reset: workaround unicode dot in systemctl output
- interfaces/udisks2: also allow Introspection on
/org/freedesktop/UDisks/**
- snap: introduce Container.RandomAccessFile
- o/ifacestate, api: implementation of snap disconnect --forget
- cmd/snap: make the portal-info command search for the network-
status interface
- interfaces: work around apparmor_parser slowness affecting uio
- tests: fix/improve failing spread tests
- many: clean separation of bootenv mocking vs mock bootloader kinds
- tests: mock prune ticker in overlord tests to reduce wait times
- travis: disable arm64 again
- httputil: add support for extra snapd certs
- travis.yml: run unit tests on arm64 as well
- many: fix a pair of ineffectual assignments
- tests: add uc20 kernel snap upgrade managers test, fix
bootloadertest bugs
- o/snapstate: set base in SnapSetup on snap revert
- interfaces/{docker,kubernetes}-support: updates for lastest k8s
- cmd/snap-exec: add test case for LP bug 1860369
- interfaces: make the network-status interface implicit on
classic
- interfaces: power control interfaceIt is documented in the
kernel
- interfaces: miscellaneous policy updates
- cmd/snap: add a "snap routine portal-info" command
- usersession/userd: add "apt" to the white list of URL schemes
handled by xdg-open
- interfaces/desktop: allow access to system prompter interface
- devicestate: allow encryption regardless of grade
- tests: run ipv6 network-retry test too
- tests: test that after "remove-user" the system is unmanaged
- snap-confine: unconditionally add /dev/net/tun to the device
cgroup
- snapcraft.yaml: use sudo -E and remove workaround
- interfaces/audio_playback: Fix pulseaudio config access
- ovelord/snapstate: update only system wide fonts cache
- wrappers: import /etc/environment in all services
- interfaces/u2f: Add Titan USB-C key
- overlord, taskrunner: exit on task/ensure error when preseeding
- tests: add session-tool, a su / sudo replacement
- wrappers: add mount unit dependency for snapd services on core
devices
- tests: just remove user when the system is not managed on create-
user-2 test
- snap-preseed: support for preseeding of snapd and core18
- boot: misc UC20 changes
- tests: adding arch-linux execution
- packaging: revert "work around review-tools and snap-confine"
- netlink: fix panic on arm64 with the new rawsockstop codewith a
nil Timeval panics
- spread, data/selinux: add CentOS 8, update policy
- tests: updating checks to new test account for snapd-test snaps
- spread.yaml: mv opensuse 15.1 to unstable
- cmd/snap-bootstrap,seed: verify only in-play snaps
- tests: use ipv4 in retry-network to unblock failing master
- data/systemd: improve the description
- client: add "Resume" to DownloadOptions and new test
- tests: enable snapd-failover on uc20
- tests: add more debug output to the snapd-failure handling
- o/devicestate: unset recovery_system when done seeding
* Fri Apr 10 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.3
- tests: fix racy pulseaudio tests
- many: fix loading apparmor profiles on Ubuntu 20.04 with ZFS
- tests: update snap-preseed --reset logic
- tests: backport partition fixes
- cmd/snap: don't wait for system key when stopping
- interfaces/many: miscellaneous policy updates xliv
- tests/main/uc20-snap-recovery: use 20.04 system
- tests: skip "/etc/machine-id" in "writablepaths
- interfaces/docker-support: add overlays file access
* Thu Apr 2 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.2
- packaging: detect/disable broken seeds in the postinst
- cmd/snap,seed: validate full seeds (UC 16/18)
- snap: add `snap debug state --is-seeded` helper
- devicestate: generate warning if seeding fails
- store: support for search API v2
- cmd/snap-seccomp/syscalls: update the list of known syscalls
- snap/cmd: the model command needs just a client, no waitMixin
- tests: cleanup security-private-tmp properly
- wrappers: fix timer schedules that are days only
- tests: update proxy-no-core to match latest CDN changes
- cmd/snap-failure,tests: make snap-failure more robust
- tests, many: don't use StartLimitInterval anymore, unify snapd-
failover variants, build snapd snap for UC16 tests
* Sat Mar 21 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44.1
- randutil: switch back to setting up seed with lower entropy data
- interfaces/greengrass-support: fix typo
- packaging,tests: ensure debian-sid builds without vendor/
- travis.yml: run unit tests with go/master as well
- cmd/snap-update-ns: ignore EROFS from rmdir/unlink
* Tue Mar 17 2020 Michael Vogt <mvo(a)ubuntu.com>
- New upstream release 2.44
- daemon: do a forceful serer shutdown if we hit a deadline
- snap: whitelist lzo as support compression for snap pack
- data/selinux: update policy to allow more ops
- interfaces/greengrass-support: add new 1.9 access
- snap: do not hardlink on overlayfs
- cmd/snap-preseed: handle --reset flag
- interfaces/kubernetes-support: allow autobind to journald socket
- snap-seccomp: allow mprotect() to unblock the tests
- tests/lib/reset: workaround unicode dot in systemctl output
- interfaces: work around apparmor_parser slowness affecting uio
- interfaces/udisks2: also allow Introspection on
/org/freedesktop/UDisks2/**
- tests: mock prune ticker in overlord tests to reduce wait times
- interfaces/{docker,kubernetes}-support: updates for lastest k8s
- interfaces: miscellaneous policy updates
- interfaces/audio_playback: Fix pulseaudio config access
- overlord: disable Test..AbortShortlyAfterStartOfOperation for 2.44
- ovelord/snapstate: update only system wide fonts cache
- wrappers: import /etc/environment in all services
- interfaces/u2f: Add Titan USB-C key
- overlord, taskrunner: exit on task/ensure error when preseeding
- overlord/snapstate/backend: update snapd services contents in unit
tests
- wrappers: add mount unit dependency for snapd services on core
devices
- Revert "tests: remove /tmp/snap.* left over by other tests"
- Revert "packaging: work around review-tools and snap-confine"
- netlink: fix panic on arm64 with the new rawsockstop code
- spread, data/selinux: add CentOS 8, update policy
- spread.yaml: mv opensuse tumbleweed to unstable too
- spread.yaml: mv opensuse 15.1 to unstable
- tests: use ipv4 in retry-network to unblock failing master
- data/systemd: improve the description
- tests/lib/prepare.sh: simplify, combine code paths
- tests/main/user-session-env: add test verifying environment
variables inside the user session
- spread.yaml: make qemu ubuntu-core-20-64 use ubuntu-20.04-64
- run-checks: SKIP_GMFMT really skips formatting checks
- tests: enable more tests for UC20/UC18
- tests: remove tmp dir for snap not-test-snapd-sh on security-
private-tmp test
- seed,cmd/snap-bootstrap: introduce seed.Snap.EssentialType,
simplify bootstrap code
- snapstate: do not restart in undoLinkSnap unless on first install
- cmd/snap-bootstrap: subcommand to detect UC chooser trigger
- cmd/snap-bootstrap/initramfs-mounts: mount the snapd snap in run-
mode too
- cmd/libsnap, tests: fix C unit tests failing as non-root
- cmd/snap-bootstrap: verify kernel snap is in modeenv before
mounting it
- tests: adding amazon linux to google backend
- cmd/snap-failure/snapd: rm snapd.socket, reset snapd.socket failed
status
- client: add support for "ResumeToken", "HeaderPeek" to download
- build: enable type: snapd
- tests: rm -rf /tmp/snap.* in restore
- cmd/snap-confine: deny snap-confine to load nss libs
- snapcraft.yaml: add comments, rename snapd part to snapd-deb
- boot: write current_kernels in bootstate20, makebootable
- packaging: work around review-tools and snap-confine
- tests: skipping interfaces-openvswitch on centos due to package is
not available
- packaging,snap-confine: stop being setgid root
- cmd/snap-confine: bring /var/lib/dhcp from host, if present
- store: rely on CommandFromSystemSnap to find xdelta3
- tests: bump sleep time of the new overlord tests
- cmd/snap-preseed: snapd version check for the target
- netlink: fix/support stopping goroutines reading netlink raw
sockets
- tests: reset PS1 before possibly interactive dash
- overlord, state: don't abort changes if spawn time before
StartOfOperationTime (2/2)
- snapcraft.yaml: add python3-apt, tzdata as build-deps for the
snapd snap
- tests: ask tar to speak English
- tests: using google storage when downloading ubuntu cloud images
from gce
- Coverity produces false positives for code like this:
- many: maybe restart & security backend options
- o/standby: add SNAPD_STANDBY_WAIT to control standby in
development
- snap: use the actual staging snap-id for snapd
- cmd/snap-bootstrap: create a new parser instance
- snapcraft.yaml: use build-base and adopt-info, rm builddeb
plugin
- tests: set StartLimitInterval in snapd failover test
- tests: disable archlinux system
- tests: add preseed test for classic
- many, tests: integrate all preseed bits and add spread tests
- daemon: support resuming downloads
- tests: use Filename() instead of filepath.Base(sn.MountFile())
- tests/core: add swapfiles test
- interfaces/cpu-control: allow to control cpufreq tunables
- interfaces: use commonInteface for desktopInterface
- interfaces/{desktop-legacy,unity7}: adjust for new ibus socket
location
- snap/info: add Filename
- bootloader: make uboot a RecoveryAwareBootloader
- gadget: skip update when mounted filesystem content is identical
- systemd: improve is-active check for 'failed' services
- boot: add current_kernels to modeenv
- o/devicestate: StartOfOperationTime helper for Prune (1/2)
- tests: detect LXD launching i386 containers
- tests: move main/ubuntu-core-* tests to core/ suite
- tests: remove snapd in ubuntu-core-snapd
- boot: enable base snap updates in bootstate20
- tests: Fix core revert channel after 2.43 has been released to
stable
- data/selinux: unify tabs/spaces
- o/ifacestate: move ResolveDisconnect to ifacestate
- spread: move centos to stable systems
- interfaces/opengl: allow datagrams to nvidia-driver
- httputil: add NoNetwork(err) helper, spread test and use in serial
acquire
- store: detect if server does not support http range headers
- test/lib/user: add helper lib for doing things for and as a user
- overlord/snapstate, wrappers: undo of snapd on core
- tests/main/interfaces-pulseaudio: use custom pulseaudio script,
set kill timeout
- store: add support for resume in DownloadStream
- cmd/snap: implement 'snap remove-user'
- overlord/devicestate: fix preseed unit tests on systems not using
/snap
- tests/main/static: ldd in glibc 2.31 logs to stderr now
- run-checks, travis: allow skipping spread jobs by adding a label
- tests: add new backend which includes images with tpm support
- boot: use constants for boot status values
- tests: add "core" suite for UC specific tests
- tests/lib/prepare: use a local copy of uc20 initramfs skeleton
- tests: retry mounting the udisk2 device due to timing issue
- usersession/client: add a client library for the user session
agent
- o/devicestate: Handle preseed mode in the firstboot mode (core16
only for now).
- boot: add TryBase and BaseStatus to modeenv; use in snap-bootstrap
- cmd/snap-confine: detect base transitions on core16
- boot: don't use "kernel" from the modeenv anymore
- interfaces: add uio interface
- tests: repack the initramfs + kernel snap for UC20 spread tests
- interfaces/greengrass-support: add /dev/null ->
/proc/latency_stats mount
- httputil: remove workaround for redirect handling in go1.7
- httputil: remove go1.6 transport workaround
- snap: add `snap pack --compression=<comp>` options
- tests/lib/prepare: fix hardcoded loopback device names for UC
images
- timeutil: add a unit test case for trivial schedule
- randutil,o/snapstate,-mkauthors.sh: follow ups to randutil
introduction
- dirs: variable with distros using alternate snap mount
- many,randutil: centralize and streamline our random value
generation
- tests/lib/prepare-restore: Revert "Continue on errors updating or
installing dependencies"
- daemon: Allow clients to call /v2/logout via Polkit
- dirs: manjaro-arm is like manjaro
- data, packaging: Add sudoers snippet to allow snaps to be run with
sudo
- daemon, store: better expose single action errors
- tests: switch mount-ns test to differential data set
- snapstate: refactor things to add the re-refresh task last
- daemon: drop support for the DELETE method
- client: move to /v2/users; implement RemoveUser
- boot: enable UC20 kernel extraction and bootState20 handling
- interfaces/policy: enforce plug-names/slot-names constraints
- asserts: parse plug-names/slot-names constraints
- daemon: make users result more consistent
- cmd/snap-confine,tests: support x.y.z nvidia version
- dirs: fixlet for XdgRuntimeDirGlob
- boot: add bootloader options to coreKernel
- o/auth,daemon: do not remove unknown user
- tests: tweak and enable tests on ubuntu 20.04
- daemon: implement user removal
- cmd/snap-confine: allow snap-confine to link to libpcre2
- interfaces/builtin: Allow NotificationReplied signal on
org.freedesktop.Notifications
- overlord/auth: add RemoveUserByName
- client: move user-related things to their own files
- boot: tweak kernel cmdline helper docstring
- osutil: implement deluser
- gadget: skip update when raw structure content is unchanged
- boot, cmd/snap, cmd/snap-bootstrap: move run mode and system label
detection to boot
- tests: fix revisions leaking from snapd-refresh test
- daemon: refactor create-user to a user action & hide behind a flag
- osutil/tests: check there are no leftover symlinks with
AtomicSymlink
- grub: support atomically renaming kernel symlinks
- osutil: add helpers for creating symlinks and renaming in an
atomic manner
- tests: add marker tag for core 20 test failure
- tests: fix gadget-update-pc test leaking snaps
- tests: remove revision leaking from ubuntu-core-refresh
- tests: remove revision leaking from remodel-kernel
- tests: disable system-usernames test on core20
- travis, tests, run-checks: skip nakedret
- tests: run `uc20-snap-recovery-encrypt` test on 20.04-64 as well
- tests: update mount-ns test tables
- snap: disable auto-import in uc20 install-mode
- tests: add a command-chain service test
- tests: use test-snapd-upower instead of upower
- data/selinux: workaround incorrect fonts cache labeling on RHEL7
- spread.yaml: fix ubuntu 19.10 and 20.04 names
- debian: check embedded keys for snap-{bootstrap,preseed} too
- interfaces/apparmor: fix doc-comments, unnecessary code
- o/ifacestate,o/devicestatate: merge gadget-connect logic into
auto-connect
- bootloader: add ExtractedRunKernelImageBootloader interface,
implement in grub
- tests: add spread test for hook permissions
- cmd/snap-bootstrap: check device size before boostrapping and
produce a meaningful error
- cmd/snap: add ability to register "snap routine" commands
- tests: add a test demonstrating that snaps can't access the
session agent socket
- api: don't return connections referring to non-existing
plugs/slots
- interfaces: refactor path() from raw-volume into utils with
comments for old
- gitignore: ignore snap files
- tests: skip interfaces-network-manager on arm devices
- o/devicestate: do not create perfTimings if not needed inside
ensureSeed/Operational
- tests: add ubuntu 20.04 to the tests execution and remove
tumbleweed from unstable
- usersession: add systemd user instance service control to user
session agent
- cmd/snap: print full channel in 'snap list', 'snap info'
- tests: remove execution of ubuntu 19.04 from google backend
- cmd/snap-boostrap: add mocking for fakeroot
- tests/core18/snapd-failover: collect more debug info
- many: run black formatter on all python files
- overlord: increase settle timeout for slow machines
- httputil: use shorter timeout in TestRetryRequestTimeoutHandling
- store, o/snapstate: send default-tracks header, use
RedirectChannel
- overlord/standby: fix possible deadlock in standby test
- cmd/snap-discard-ns: fix pattern for .info files
- boot: add HasModeenv to Device
- devicestate: do not allow remodel between core20 models
- bootloader,snap: misc tweaks
- store, overlord/snapstate, etc: SnapAction now returns a []���Result
- snap-bootstrap: create encrypted partition
- snap: remove "host" output from `snap version`
- tests: use snap remove --purge flag in most of the spread tests
- data/selinux, test/main/selinux-clean: update the test to cover
more scenarios
- many: drop NameAndRevision, use snap.PlaceInfo instead
- boot: split MakeBootable tests into their own file
- travis-ci: add go import path
- boot: split MakeBootable implementations into their own file
- tests: enable a lot of the tests of main on uc20
- packaging, tests: stop services in prerm
- tests: enable regression suite on core20
- overlord/snapstate: improve snapd snap backend link unit tests
- boot: implement SetNextBoot in terms of bootState.setNext
- wrappers: write and undo snapd services on core
- boot,o/devicestate: refactor MarkBootSuccessful over bootState
- snap-bootstrap: mount the correct snapd snap to /run/mnt/snapd
- snap-bootstrap: refactor partition creation
- tests: use new snapd.spread-tests-run-mode-tweaks.service unit
- tests: add core20 tests
- boot,o/snapstate: SetNextBoot/LinkSnap return whether to reboot,
use the information
- tests/main/snap-sign: add test for non-stdin signing
- snap-bootstrap: trigger udev after filesystem creation
- boot,overlord: introduce internal abstraction bootState and use it
for InUse/GetCurrentBoot
- overlord/snapstate: tracks are now sticky
- cmd: sign: add filename param
- tests: remove "test-snapd-tools" in smoke/sandbox on restore
- cmd/snap, daemon: stop over-normalising channels
- tests: fix classic-ubuntu-core-transition-two-cores after refactor
of MATCH -v
- packaging: ship var/lib/snapd/desktop/applications in the pkg
- spread: drop copr repo with F30 build dependencies
- tests: use test-snapd-sh snap instead of test-snapd-tools - Part 3
- tests: fix partition creation test
- tests: unify/rename services-related spread tests to start with
services- prefix
- test: extract code that modifies "writable" for test prep
- systemd: handle preseed mode
- snap-bootstrap: read only stdout when parsing the sfdisk json
- interfaces/browser-support: add more product/vendor paths
- boot: write compat UC16 bootvars in makeBootable20RunMode
- devicestate: avoid adding mockModel to deviceMgrInstallModeSuite
- devicestate: request reboot after successful doSetupRunSystem()
- snapd.core-fixup.sh: do not run on UC20 at all
- tests: unmount automounted snap-bootstrap devices
- devicestate: run boot.MakeBootable in doSetupRunSystem
- boot: copy kernel/base to data partition in makeBootable20RunMode
- tests: also check nested lxd container
- run-checks: complain about MATCH -v
- boot: always return the trivial boot participant in ephemeral mode
- o/devicestate,o/snapstate: move the gadget.yaml checkdrive-by: use
gadget.ReadInfoFromSnapFile in checkGadgetRemodelCompatible
- snap-bootstrap: append new partitions
- snap-bootstrap: mount filesystems after creation
- snapstate: do not try to detect rollback in ephemeral modes
- snap-bootstrap: trigger udev for new partitions
- cmd/snap-bootstrap: xxx todos about kernel cross-checks
- tests: avoid mask rsyslog service in case is not enabled on the
system
- tests: fix use of MATCH -v
- cmd/snap-preseed: update help strings
- cmd/snap-bootstrap: actually parse snapd_recovery_system label
- bootstrap: reduce runmode mounts from 5 to 2 steps.
- lkenv.go: adjust for new location of include file
- snap: improve squashfs.ReadFile() error
- systemd: fix uc20 shutdown
- boot: write modeenv when creating the run mode
- boot,image: add skeleton boot.makeBootable20RunMode
- cmd/snap-preseed: add snap-preseed executable
- overlord,boot: follow ups to #7889 and #7899
- interfaces/wayland: Add access to Xwayland's shm files
- o/hookstate/ctlcmd: fix command name in snapctl -h
- daemon,snap: remove screenshot deprecation notice
- overlord,o/snapstate: make sure we never leave config behind
- many: pass consistently boot.Device state to boot methods
- run-checks: check multiline string blocks in
restore/prepare/execute sections of spread tests
- intrefaces: login-session-control - added missing dbus commands
- tests/main/parallel-install-remove-after: parallel installs should
not break removal
- overlord/snapstate: tweak assumes error hint
- overlord: replace DeviceContext.OldModel with GroundContext
- devicestate: use httputil.ShouldRetryError() in
prepareSerialRequest
- tests: replace "test-snapd-base-bare" with real "bare" base snap
- many: pass a Model to the gadget info reading functions
- snapstate: relax gadget constraints in ConfigDefaults Et al.
- devicestate: only run ensureBootOk() in "run" mode
- tests/many: quiet lxc launching, file pushing
- tests: disable apt-hooks test until it can be properly fixed
- tests: 16.04 and 18.04 now have mediating pulseaudio
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1811793 - snapd-glib-1.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1811793
[ 2 ] Bug #1814552 - snapd-2.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1814552
--------------------------------------------------------------------------------
================================================================================
snapd-glib-1.57-1.el7 (FEDORA-EPEL-2020-6e69f4cf75)
Library providing a GLib interface to snapd
--------------------------------------------------------------------------------
Update Information:
Update to `snapd-2.45` and `snapd-glib-1.57`
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 Neal Gompa <ngompa13(a)gmail.com> - 1.57-1
- Update to 1.57
- Add snapd_interface_make_label
- Add support for new snap types: "core", "base" and "snapd"
- Change way GTK documentation is generated to avoid a Meson bug
- Fix leak in markdown parser
- Fix leak in logout code
- Make build reproducible by fixing comment in generated file
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1811793 - snapd-glib-1.57 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1811793
[ 2 ] Bug #1814552 - snapd-2.45 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1814552
--------------------------------------------------------------------------------
================================================================================
zstd-1.4.5-3.el7 (FEDORA-EPEL-2020-d4cafc9395)
Zstd compression library
--------------------------------------------------------------------------------
Update Information:
Build shared library with correct compiler flags
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2020 P��draig Brady <P(a)draigBrady.com> - 1.4.5-3
- Build shared library with correct compiler flags
* Fri May 22 2020 P��draig Brady <P(a)draigBrady.com> - 1.4.5-1
- Latest upstream
* Fri May 22 2020 Avi Kivity <avi(a)scylladb.com> - 1.4.4-3
- Added static library subpackage
* Fri Jan 31 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.4.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
--------------------------------------------------------------------------------
Hi all.
`libb2-0.98.1` has been required on F31 [1] and EPEL7 [2]; it expects a
soname bump, so all dependent packages need to be rebuilt:
$ repoquery --whatrequires libb2-devel --disablerepo=*
--enablerepo=*-source
R-argon2-0:0.2.0-8.fc32.src
borgbackup-0:1.1.11-1.fc32.src
gtkhash-0:1.2-2.fc32.src
--
---
Antonio Trande
Fedora Project
mailto 'sagitter at fedoraproject dot org'
GPG key: 0x7B30EE04E576AA84
GPG key server: https://keys.openpgp.org/
The following Fedora EPEL 6 Security updates need testing:
Age URL
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-db3d7a1399 exim-4.92.3-2.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-d5bbc97415 json-c12-0.12.1-4.el6
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fe619e5492 golang-1.13.11-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
sympa-6.2.56-1.el6
Details about builds:
================================================================================
sympa-6.2.56-1.el6 (FEDORA-EPEL-2020-ffaa79c364)
Powerful multilingual List Manager
--------------------------------------------------------------------------------
Update Information:
Update to sympa 6.2.56. Fixes CVE-2020-10936. For details, see: -
https://github.com/sympa-community/sympa/releases/tag/6.2.56 - https://sympa-
community.github.io/security/2020-002.html
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 24 2020 Xavier Bachelot <xavier(a)bachelot.org> 6.2.56-1
- Update to 6.2.56 (Fixes CVE-2020-10936)
- Fix typo in url and also socket location in lighttpd configuration (RHBZ#1812325)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1770783 - multicomponent wwsympa_url with mod_proxy_fcgi is broken
https://bugzilla.redhat.com/show_bug.cgi?id=1770783
[ 2 ] Bug #1812325 - Migration with lighttpd is broken
https://bugzilla.redhat.com/show_bug.cgi?id=1812325
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-765ceaa306 clamav-0.102.3-1.el8
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-30aba92944 log4net-2.0.8-10.el8
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-2056b1c4a9 exim-4.93-3.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-5660594875 python-markdown2-2.3.9-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-c3fca161ee netdata-1.22.1-3.el8
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-38309f9f6f transmission-2.94-9.el8
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-06e970da9c knot-resolver-5.1.1-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
gloox-1.0.23-1.el8
nagios-plugins-2.3.3-3.el8
perl-Email-MIME-1.949-1.el8
perl-Email-MIME-ContentType-1.024-1.el8
python-oletools-0.55-2.el8
rancid-3.11-1.el8
testdisk-7.1-3.el8
Details about builds:
================================================================================
gloox-1.0.23-1.el8 (FEDORA-EPEL-2020-65f631d3ca)
A rock-solid, full-featured Jabber/XMPP client C++ library
--------------------------------------------------------------------------------
Update Information:
Build gloox for EPEL 8
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
================================================================================
nagios-plugins-2.3.3-3.el8 (FEDORA-EPEL-2020-fda19f40be)
Host/service/network monitoring program plugins for Nagios
--------------------------------------------------------------------------------
Update Information:
Obsolete check_ssl_validity. To be reinstated when CentOS 8.2 is released.
BZ#1837397 ---- Remove ssl_validity as perl-Convert-ASN1 has been retired.
BZ#1837397
--------------------------------------------------------------------------------
ChangeLog:
* Mon Oct 13 2003 Martin Jackson <mhjacks(a)swbell.net> - 2.3.3-3
- Obsolete check_ssl_validity. To be reinstated when CentOS 8.2 is released. BZ#1837397
* Wed Oct 8 2003 Martin Jackson <mhjacks(a)swbell.net> - 2.3.3-2
- Remove ssl_validity as perl-Convert-ASN1 has been retired. BZ#1837397
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1837397 - Can't install "nagios-plugins-all" because "perl-Convert-ASN1" is missing for RHEL 8 / CentOS 8
https://bugzilla.redhat.com/show_bug.cgi?id=1837397
--------------------------------------------------------------------------------
================================================================================
perl-Email-MIME-1.949-1.el8 (FEDORA-EPEL-2020-383149ca50)
Easy MIME message parsing
--------------------------------------------------------------------------------
Update Information:
This update limits the number of nested MIME parts to 10 (by default), to avoid
a possible memory exhaustion issue with lots of tiny MIME parts.
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 24 2020 Paul Howarth <paul(a)city-fan.org> - 1.949-1
- Update to 1.949
- Add $Email::MIME::MAX_DEPTH and refuse to parse deeper than that many
parts; current default: 10
- Fixes to handling of content-type parameters
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1835353 - rubygem-mail: Out of memory issue through nested MIME parts
https://bugzilla.redhat.com/show_bug.cgi?id=1835353
--------------------------------------------------------------------------------
================================================================================
perl-Email-MIME-ContentType-1.024-1.el8 (FEDORA-EPEL-2020-383149ca50)
Parse a MIME Content-Type Header
--------------------------------------------------------------------------------
Update Information:
This update limits the number of nested MIME parts to 10 (by default), to avoid
a possible memory exhaustion issue with lots of tiny MIME parts.
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 24 2020 Paul Howarth <paul(a)city-fan.org> - 1.024-1
- Update to 1.024
- Silence an uninitialized value warning
- Avoid allowing non-Latin digits in numbers
- Add new functions build_content_type() and build_content_disposition()
* Wed Jan 29 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.022-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1835353 - rubygem-mail: Out of memory issue through nested MIME parts
https://bugzilla.redhat.com/show_bug.cgi?id=1835353
--------------------------------------------------------------------------------
================================================================================
python-oletools-0.55-2.el8 (FEDORA-EPEL-2019-3a67d5246c)
Tools to analyze Microsoft OLE2 files
--------------------------------------------------------------------------------
Update Information:
bump to bugfix release 0.55
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jan 30 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.55-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Wed Dec 4 2019 Michal Ambroz <rebus AT_ seznam.cz> - 0.55-1
- bump to bugfix release 0.55
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1779427 - python-oletools-0.55 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1779427
--------------------------------------------------------------------------------
================================================================================
rancid-3.11-1.el8 (FEDORA-EPEL-2020-684bead341)
Really Awesome New Cisco confIg Differ
--------------------------------------------------------------------------------
Update Information:
New package for EL8
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1838666 - Build rancid for EL8
https://bugzilla.redhat.com/show_bug.cgi?id=1838666
--------------------------------------------------------------------------------
================================================================================
testdisk-7.1-3.el8 (FEDORA-EPEL-2020-fea6659910)
Tool to check and undelete partition, PhotoRec recovers lost files
--------------------------------------------------------------------------------
Update Information:
libewf-devel is available in rhel8
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 24 2020 Christophe Grenier <grenier(a)cgsecurity.org> - 7.1-3
- libewf-devel is available in rhel8
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
648 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d condor-8.6.11-1.el7
390 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-c499781e80 python-gnupg-0.4.4-1.el7
388 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-bc0182548b bubblewrap-0.3.3-2.el7
97 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fa8a2e97c6 python-waitress-1.4.3-1.el7
37 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19d171a465 python34-3.4.10-5.el7
13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-e6847d3b59 perl-Mojolicious-7.94-3.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff94ccbdec openssl11-1.1.1c-2.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-624f38e579 qbittorrent-3.3.16-2.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-235a51a239 clamav-0.102.3-1.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ae83e43288 log4net-2.0.8-10.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-134c471656 json-c12-0.12.1-4.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-567eda5296 exim-4.93-3.el7
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff11142989 netdata-1.22.1-3.el7
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-e7814b7723 transmission-2.94-9.el7
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19de895038 knot-resolver-5.1.1-1.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ed6bc3c8d4 golang-1.13.11-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
opensmtpd-6.7.1p1-1.el7
rdiff-backup-2.0.3-1.el7
tracer-0.7.3-2.el7
xrootd-4.12.1-1.el7
Details about builds:
================================================================================
opensmtpd-6.7.1p1-1.el7 (FEDORA-EPEL-2020-c8b359dff8)
Free implementation of the server-side SMTP protocol as defined by RFC 5321
--------------------------------------------------------------------------------
Update Information:
OpenSMTPD 6.7.1p1 (May 21, 2020) --- - a packaging issue causing asr.h to be
installed on the host system - a possible crash when the MTA establishes an IPv6
connection OpenSMTPD 6.7.0p1 (May 21, 2020) --- New Features: - Allowed use of
the smtpd(8) session username in built-in filters when available. - Introduced a
bypass keyword to smtpd(8) so that built-in filters can bypass processing when a
condition is met. - Allowed use of 'auth' as an origin in smtpd.conf(5). -
Allowed use of mail-from and rctp-to as for and from parameters in
smtpd.conf(5). Bug fixes: - Ensured legacy ssl(8) session ID is persistent
during a client TLS session, fixing an issue using TLSv1.3 with
smtp.mail.yahoo.com. - Fixed security vulnerabilities in smtpd(8). Corrected an
out-of-bounds read in smtpd allowing an attacker to inject arbitrary commands
into the envelope file to be executed as root, and ensured privilege revocation
in smtpctl(8) to prevent arbitrary commands from being run with the _smtpq
group. - Allowed mail.local(8) to be run as non-root, opening a pipe to
lockspool(1) for file locking. - Fixed a security vulnerability in smtpd(8)
which could lead to a privilege escalation on mbox deliveries and unprivileged
code execution on lmtp deliveries. - Added support for CIDR in a: spf atoms in
smtpd(8). - Fixed a possible crash in smtpd(8) when combining "from rdns" with
nested virtual aliases under a particular configuration. Experimental Features:
- Introduced smtp-out event reporting. - Improved filtering protocol.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 22 2020 Denis Fateyev <denis(a)fateyev.com> - 6.7.1p1-1
- Update to 6.7.1p1 release
- Remove deprecated "legacy_common_support" build option
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1835478 - opensmtpd-6.7.1p1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1835478
--------------------------------------------------------------------------------
================================================================================
rdiff-backup-2.0.3-1.el7 (FEDORA-EPEL-2020-150c0a4ed4)
Convenient and transparent local/remote incremental mirror/backup
--------------------------------------------------------------------------------
Update Information:
Version 2.0.3 - Bugfix release
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Frank Crawford <frank(a)crawford.emu.id.au> 2.0.3-1
- Version 2.0.3 - Bugfix release
--------------------------------------------------------------------------------
================================================================================
tracer-0.7.3-2.el7 (FEDORA-EPEL-2020-d7757e6460)
Finds outdated running applications in your system
--------------------------------------------------------------------------------
Update Information:
- Use DNF on RHEL (jturel(a)gmail.com) - Use PackageManager to determine kernel
version (jturel(a)gmail.com) - Use subprocess to check process path arguments
(jturel(a)gmail.com) - Ignore debug kernels when checking if kernel has been
updated (jturel(a)gmail.com) - Fix build dependencies for EL7, EL8, F30
(jturel(a)gmail.com) - Do not build python2 package for Fedora anymore
(frostyx(a)email.cz)
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Jakub Kadl����k <jkadlcik(a)redhat.com> - 0.7.3-2
- We lost release dist macro somewhere
* Fri May 22 2020 Jonathon Turel <jturel(a)gmail.com> 0.7.3-1
- Stub dbus calls in tests (jturel(a)gmail.com)
* Thu May 21 2020 Jonathon Turel <jturel(a)gmail.com> 0.7.2-3
- Update tito releaser branches (frostyx(a)email.cz)
- Not build for python2 package for Fedora anymore (frostyx(a)email.cz)
* Thu May 21 2020 Jonathon Turel <jturel(a)gmail.com> 0.7.2-2
- Fix build dependencies for EL7, EL8, F30 (jturel(a)gmail.com)
* Thu May 21 2020 Jonathon Turel <jturel(a)gmail.com> 0.7.2-1
- Use DNF on RHEL (jturel(a)gmail.com)
- Use PackageManager to determine kernel version (jturel(a)gmail.com)
- Use subprocess to check process path arguments (jturel(a)gmail.com)
- Find the right lxml version for Python 3.4 (jturel(a)gmail.com)
- Update Vagrantfile to use Fedora 30 (jturel(a)gmail.com)
- Ignore debug kernels when checking if kernel has been updated
(jturel(a)gmail.com)
- Add build dependency for nosetests (frostyx(a)email.cz)
- Run tests within the %check phase (frostyx(a)email.cz)
- Update fedora branches (frostyx(a)email.cz)
--------------------------------------------------------------------------------
================================================================================
xrootd-4.12.1-1.el7 (FEDORA-EPEL-2020-8583f8d850)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
xrootd 4.12.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 21 2020 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:4.12.1-1
- Update to version 4.12.1
- Fix broken man page
--------------------------------------------------------------------------------
The following Fedora EPEL 6 Security updates need testing:
Age URL
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-d5bbc97415 json-c12-0.12.1-4.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-db3d7a1399 exim-4.92.3-2.el6
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fe619e5492 golang-1.13.11-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
xrootd-4.12.1-1.el6
Details about builds:
================================================================================
xrootd-4.12.1-1.el6 (FEDORA-EPEL-2020-5f7565fcf4)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
xrootd 4.12.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 21 2020 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:4.12.1-1
- Update to version 4.12.1
- Fix broken man page
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-0d41abf072 perl-Mojolicious-8.42-1.el8
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-765ceaa306 clamav-0.102.3-1.el8
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-30aba92944 log4net-2.0.8-10.el8
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-2056b1c4a9 exim-4.93-3.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-5660594875 python-markdown2-2.3.9-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-c3fca161ee netdata-1.22.1-3.el8
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-38309f9f6f transmission-2.94-9.el8
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-06e970da9c knot-resolver-5.1.1-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
blosc-1.17.0-2.el8
marked-1.1.0-3.el8
opensmtpd-6.7.1p1-1.el8
openvdb-7.0.0-3.el8
python-empy-3.3.4-6.el8
rdiff-backup-2.0.3-1.el8
tmt-0.17-1.el8
tracer-0.7.3-2.el8
vim-devicons-0.11.0-3.20200509gitd12c9b4.el8
vim-gitgutter-0-4.20200501gitb356cc9.el8
vim-gv-0-5.20200522git61d877d.el8
xrootd-4.12.1-1.el8
Details about builds:
================================================================================
blosc-1.17.0-2.el8 (FEDORA-EPEL-2020-2488a2167f)
High performance compressor optimized for binary data
--------------------------------------------------------------------------------
Update Information:
Fix dependency on libzstd.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 22 2020 Zbigniew J��drzejewski-Szmek <zbyszek(a)in.waw.pl> - 1.17.0-2
- Use bundled libztd on epel8
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1839069 - blosc uninstallable on EPEL 8
https://bugzilla.redhat.com/show_bug.cgi?id=1839069
--------------------------------------------------------------------------------
================================================================================
marked-1.1.0-3.el8 (FEDORA-EPEL-2020-e333444450)
A markdown parser for Node.js built for speed
--------------------------------------------------------------------------------
Update Information:
New upstream release, many bug an security fixes. New package for EPEL8.
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
================================================================================
opensmtpd-6.7.1p1-1.el8 (FEDORA-EPEL-2020-1e7a059747)
Free implementation of the server-side SMTP protocol as defined by RFC 5321
--------------------------------------------------------------------------------
Update Information:
OpenSMTPD 6.7.1p1 (May 21, 2020) --- - a packaging issue causing asr.h to be
installed on the host system - a possible crash when the MTA establishes an IPv6
connection OpenSMTPD 6.7.0p1 (May 21, 2020) --- New Features: - Allowed use of
the smtpd(8) session username in built-in filters when available. - Introduced a
bypass keyword to smtpd(8) so that built-in filters can bypass processing when a
condition is met. - Allowed use of 'auth' as an origin in smtpd.conf(5). -
Allowed use of mail-from and rctp-to as for and from parameters in
smtpd.conf(5). Bug fixes: - Ensured legacy ssl(8) session ID is persistent
during a client TLS session, fixing an issue using TLSv1.3 with
smtp.mail.yahoo.com. - Fixed security vulnerabilities in smtpd(8). Corrected an
out-of-bounds read in smtpd allowing an attacker to inject arbitrary commands
into the envelope file to be executed as root, and ensured privilege revocation
in smtpctl(8) to prevent arbitrary commands from being run with the _smtpq
group. - Allowed mail.local(8) to be run as non-root, opening a pipe to
lockspool(1) for file locking. - Fixed a security vulnerability in smtpd(8)
which could lead to a privilege escalation on mbox deliveries and unprivileged
code execution on lmtp deliveries. - Added support for CIDR in a: spf atoms in
smtpd(8). - Fixed a possible crash in smtpd(8) when combining "from rdns" with
nested virtual aliases under a particular configuration. Experimental Features:
- Introduced smtp-out event reporting. - Improved filtering protocol.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 22 2020 Denis Fateyev <denis(a)fateyev.com> - 6.7.1p1-1
- Update to 6.7.1p1 release
- Remove deprecated "legacy_common_support" build option
* Fri Apr 10 2020 Denis Fateyev <denis(a)fateyev.com> - 6.6.4p1-3
- Rebuilt for epel7 compatibility
* Fri Feb 28 2020 Denis Fateyev <denis(a)fateyev.com> - 6.6.4p1-2
- Add "legacy_common_support" build option
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1835478 - opensmtpd-6.7.1p1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1835478
--------------------------------------------------------------------------------
================================================================================
openvdb-7.0.0-3.el8 (FEDORA-EPEL-2020-7511fc230b)
C++ library for sparse volumetric data discretized on three-dimensional grids
--------------------------------------------------------------------------------
Update Information:
Add support for Red Hat Enterprise Linux 8 and its derivatives
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1839088 - Please support EPEL 8 branch of openvdb
https://bugzilla.redhat.com/show_bug.cgi?id=1839088
--------------------------------------------------------------------------------
================================================================================
python-empy-3.3.4-6.el8 (FEDORA-EPEL-2020-3071a6b022)
A powerful and robust template system for Python
--------------------------------------------------------------------------------
Update Information:
release 3.3.4 for EPEL8
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1809357 - Please build an EPEL8 build for python-empy
https://bugzilla.redhat.com/show_bug.cgi?id=1809357
--------------------------------------------------------------------------------
================================================================================
rdiff-backup-2.0.3-1.el8 (FEDORA-EPEL-2020-41a1f1196c)
Convenient and transparent local/remote incremental mirror/backup
--------------------------------------------------------------------------------
Update Information:
Version 2.0.3 - Bugfix release
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Frank Crawford <frank(a)crawford.emu.id.au> 2.0.3-1
- Version 2.0.3 - Bugfix release
--------------------------------------------------------------------------------
================================================================================
tmt-0.17-1.el8 (FEDORA-EPEL-2020-6898d837d9)
Test Management Tool
--------------------------------------------------------------------------------
Update Information:
Dynamic plugins, step wake up, packaging cleanup
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Petr ��pl��chal <psplicha(a)redhat.com> - 0.17-1
- Use emulator_path instead of hard-coded qemu path
- Improve a bit the --force option description
- Use consistent naming for provision subpackages
- Add 'mock' to extra requires (needed to make docs)
- Move podman and testcloud plugins into subpackages
- Enable epel for packit build & testing farm
- Move vagrant from requires to recommends (tmt-all)
* Mon May 18 2020 Petr ��pl��chal <psplicha(a)redhat.com> - 0.16-1
- Merge the fix and test for run --force [#245]
- Merge the improved display report [#241]
- Adjust the display report plugin verbose output
- Adjust general plan linking and component check
- Clean up the run workdir if --force provided
- More verbose modes for report --how display
- Link plans, handle missing components in export
- Import and listify of contact
- Disable Tier 3 tests by default (need bare metal)
- Move Tier 0 tests into a separate directory
- Merge the new 1minutetip provision plugin [#225]
- Adjust the 1minutetip provision plugin
- Add support for tmt run --after and --before (#237)
- Support string in test component, require and tag (#233)
- Add support for installing local rpm packages
- Add 1minutetip provision plugin
- Implement tmt run --since, --until and --skip (#236)
- Merge pull request #234 from psss/testcloud-aliases
- Update the last run id at the very end of run
- Support short Fedora compose aliases in testcloud
- Convert the finish step into dynamic plugins
- Convert the report step into dynamic plugins
- Convert the execute step into dynamic plugins
- Escape package names during installation
- Deduplicate inherited keys in test import [fix #8]
* Wed Apr 29 2020 Petr ��pl��chal <psplicha(a)redhat.com> - 0.15-1
- Implement executing the last run using --last
- Adjust support for modifying plan templates
- Add a way how to edit values in a new template
- Explicitly mention supported distros in the docs
- Convert provision/prepare into dynamic plugins
- Describe difference between --verbose and --debug
- Support fmf name references in docs, update spec
- Support multiple verbose/debug levels [fix #191]
- Remove forgotten 'Core' section from stories
- Implement Plugin.show() for a full dynamic support
- Improve the workdir handling in the Common class
* Thu Apr 16 2020 Petr ��pl��chal <psplicha(a)redhat.com> - 0.14-1
- Workaround yaml key sorting on rhel-8 [fix #207]
- Fix test discovery from the execute step scripts
- Merge discover step documentation and fixes [#204]
- Document the discover step, fix issues, add tests
- Simplify the minimal example, adjust tests
- Move fmf_id() to Node class, minor adjustments
- Allow to print fmf identifier in tmt tests show
- Merge manual tests story and examples [#198]
- Add a story and examples describing manual tests
- Sync more extra-* attributes when exporting [#199]
- Enable checks for essential test attributes
- Handle require in Dicovery
- Store imported metadata in a sane order [fix #86]
- Enable Python 3.8 in Travis, update classifiers
- Add missing 'require' attribute to the Test class
- Fix long environment for run.sh [fix #126]
- Merge dynamic plugins and wake up support [#186]
- Implement dynamic plugins and options [fix #135]
- Suggest using 'tmt init' when metadata not found
- Merge improved import of tier from tags [#187]
- Adjust tier import from test case tags
- Merge tmt test export --nitrate --create [#185]
- Adjust suppport for creating new nitrate testcases
- Allow creation of nitrate cases when exporting
- Create tier attribute from multiple Tier tags
- Fix run.sh to work with RHEL/CentOS 7 as well
- Implement wake up for Run, Step and Discover
* Wed Apr 1 2020 Petr ��pl��chal <psplicha(a)redhat.com> - 0.13-1
- Merge the improved test import checks [#179]
- Adjust checks for missing metadata
- Add checks for missing metadata.
- Implement public_git_url() for git url conversion
- Define required attributes and duration default
--------------------------------------------------------------------------------
================================================================================
tracer-0.7.3-2.el8 (FEDORA-EPEL-2020-c8fdb301c5)
Finds outdated running applications in your system
--------------------------------------------------------------------------------
Update Information:
- Use DNF on RHEL (jturel(a)gmail.com) - Use PackageManager to determine kernel
version (jturel(a)gmail.com) - Use subprocess to check process path arguments
(jturel(a)gmail.com) - Ignore debug kernels when checking if kernel has been
updated (jturel(a)gmail.com) - Fix build dependencies for EL7, EL8, F30
(jturel(a)gmail.com) - Do not build python2 package for Fedora anymore
(frostyx(a)email.cz)
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
================================================================================
vim-devicons-0.11.0-3.20200509gitd12c9b4.el8 (FEDORA-EPEL-2020-edc884cdf9)
Adds file type icons to Vim plugins
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Artem Polishchuk <ego.cordatus(a)gmail.com> - 0.11.0-3.20200509gitd12c9b4
- Update to latest git snapshot
* Fri Jan 31 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.11.0-2.20191110gite3e6aa1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
vim-gitgutter-0-4.20200501gitb356cc9.el8 (FEDORA-EPEL-2020-6da6a696e8)
Shows a git diff in the gutter and stages/undoes hunks and partial hunks
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Artem Polishchuk <ego.cordatus(a)gmail.com> - 0-4.20200501gitb356cc9
- Update to latest git snapshot
--------------------------------------------------------------------------------
================================================================================
vim-gv-0-5.20200522git61d877d.el8 (FEDORA-EPEL-2020-fc63e6dec3)
Git commit browser in Vim
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 23 2020 Artem Polishchuk <ego.cordatus(a)gmail.com> - 0-5.20200522git61d877d
- Update to latest git snapshot
--------------------------------------------------------------------------------
================================================================================
xrootd-4.12.1-1.el8 (FEDORA-EPEL-2020-c90cc05f01)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
xrootd 4.12.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 21 2020 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1:4.12.1-1
- Update to version 4.12.1
- Fix broken man page
--------------------------------------------------------------------------------