Weekly portage-stable package updates 2026-08-03 - #4173
Weekly portage-stable package updates 2026-08-03#4173github-actions[bot] wants to merge 197 commits into
Conversation
683249d to
6f5965e
Compare
6f5965e to
c3c2756
Compare
c3c2756 to
c81c02f
Compare
c81c02f to
d2a5e3c
Compare
d2a5e3c to
2f8968f
Compare
85c5ba0 to
084df81
Compare
084df81 to
ef55a48
Compare
|
CI finally passed. |
It's from Gentoo commit 26eea6f0bd95ba783f861e590012f0f0abb77117. Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
It's from Gentoo commit 8861c37e3fe818881fc80a944bb0da1fe2817b42. Signed-off-by: Flatcar Buildbot <buildbot@flatcar-linux.org>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…cies With the fixes in selinux-policy-2.eclass, we can go back to the single patch for all the selinux policy packages. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
… to env overrides Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
But this time yell quite loud about it, so it will be visible in the occurences file. And I will remember to reinstate it next time instead of spending more time to investigate it. But at least the investigation resulted in dropping the patch - it is enough to just regenerate the build system. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
This is a workaround for a cross-compilation issue. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…s/lvm2 Did not break anything, because the post-processing of tmpfiles does not modify this one. Noticed when dealing with audit's config file. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
…es 3.11 The issue we are working around is SELinuxProject/selinux#540. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
ef55a48 to
8cceb92
Compare
That seems broken. 1.14_p20260502 is unkeyworded, so we haven't taken that version. |
|
Oh okay, I see you've overridden that. I wonder why Gentoo didn't keyword it. |
Yeah, I sometimes override stuff for security fixes. Dunno about missing keywords, though. |
| - base, dev: libsemanage ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11) (includes [3.10](https://github.com/SELinuxProject/selinux/releases/tag/3.10), [3.9](https://github.com/SELinuxProject/selinux/releases/tag/3.9))) | ||
| - base, dev: libsepol ([3.11](https://github.com/SELinuxProject/selinux/releases/tag/3.11)) | ||
| - base, dev: nghttp2 ([1.69.0](https://github.com/nghttp2/nghttp2/releases/tag/v1.69.0)) | ||
| - base, dev: ngtcp2 ([1.24.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.2{4,3}.0) (includes [1.23.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.23.0))) |
There was a problem hiding this comment.
Broken link. Should be:
- base, dev: ngtcp2 ([1.24.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.24.0) (includes [1.23.0](https://github.com/ngtcp2/ngtcp2/releases/tag/v1.23.0)))
| - dev: sandbox ([2.49](https://gitweb.gentoo.org/proj/sandbox.git/log/?h=v2.49)) | ||
| - sysext-containerd: containerd ([2.3.3](https://github.com/containerd/containerd/releases/tag/v2.3.3) (includes [2.3.2](https://github.com/containerd/containerd/releases/tag/v2.3.2), [2.3.1](https://github.com/containerd/containerd/releases/tag/v2.3.1), [2.3.0](https://github.com/containerd/containerd/releases/tag/v2.3.0))) | ||
| - sysext-docker: docker ([29.5.2](https://github.com/moby/moby/releases/tag/docker-v29.5.2) (includes [29.5.1](https://github.com/moby/moby/releases/tag/docker-v29.5.1), [29.5.0](https://github.com/moby/moby/releases/tag/docker-v29.5.0), [29.4.0](https://github.com/moby/moby/releases/tag/docker-v29.4.0), [29.3.0](https://github.com/moby/moby/releases/tag/docker-v29.3.0), [29.2.0](https://github.com/moby/moby/releases/tag/docker-v29.2.0))) | ||
| - sysext-docker: docker-buildx ([0.35.0](https://github.com/docker/buildx/releases/tag/v0.36.0)) |
There was a problem hiding this comment.
Typo, should be:
- sysext-docker: docker-buildx ([0.35.0](https://github.com/docker/buildx/releases/tag/v0.35.0))
| ## THIS IS A RARE FLATCAR MODIFICATION IN PORTAGE-STABLE EBUILD. | ||
| ## REINSTATE IT AFTER WEEKLY UPDATES AUTOMATION CLOBBERS IT AGAIN. WE | ||
| ## NEED TO KEEP IT UNTIL WE UPDATE TO BIND 9.21 (USES MESON) OR GENTOO | ||
| ## UPDATES THE EBUILD TO DO THE SAME THING. |
There was a problem hiding this comment.
If I understand the comment correctly, we need to repeat remembering adding Flatcar-specific inherit autotools on every upcoming weekly updates, until Gentoo at some point is able to have bind 9.21, right? Isn't it too error-prone?
Because AFAIK Gentoo still has bind 9.20.26 as stable, not 9.21.
Why don't we simply move bind to coreos-overlay, until bind 9.21 could be available?
Or is there some discussion upstream going on that I am not aware of?

CI: https://jenkins.flatcar.org/job/container/job/sdk/133/cldsv/
Closes flatcar/Flatcar#1693
Closes flatcar/Flatcar#2068
Closes flatcar/Flatcar#2079
Closes flatcar/Flatcar#2124
Closes flatcar/Flatcar#2173
Closes flatcar/Flatcar#2175
Closes flatcar/Flatcar#2179
Closes flatcar/Flatcar#2182
Closes flatcar/Flatcar#2189
Closes flatcar/Flatcar#2190
Closes flatcar/Flatcar#2191
Closes flatcar/Flatcar#2192
Closes flatcar/Flatcar#2195
Closes flatcar/Flatcar#2196
Closes flatcar/Flatcar#2197
Closes flatcar/Flatcar#2199
Closes flatcar/Flatcar#2207
Closes flatcar/Flatcar#2209
Closes flatcar/Flatcar#2210
Closes flatcar/Flatcar#2211
Closes flatcar/Flatcar#2212
Closes flatcar/Flatcar#2220
Closes flatcar/Flatcar#2222
Closes flatcar/Flatcar#2224
Closes flatcar/Flatcar#2225
Closes flatcar/Flatcar#2242
Closes flatcar/Flatcar#2258
Partially addresses flatcar/Flatcar#2142
Partially addresses flatcar/Flatcar#2169
--
app-admin/logrotate: [PROD] [DEV]
app-arch/bzip2: [TODO]
app-arch/gzip: [PROD] [DEV]
app-arch/libarchive: [PROD] [DEV]
app-arch/tar: [PROD] [DEV]
app-containers/container-libs: [SYSEXT-PODMAN]
app-containers/containerd: [SYSEXT-CONTAINERD]
app-containers/cri-tools: [PROD] [DEV]
app-containers/docker: [SYSEXT-DOCKER]
app-containers/docker-buildx: [SYSEXT-DOCKER]
app-containers/docker-cli: [SYSEXT-DOCKER]
app-containers/netavark: [SYSEXT-PODMAN]
app-containers/podman: [SYSEXT-PODMAN]
app-crypt/mit-krb5: [PROD] [DEV]
app-crypt/p11-kit: [PROD] [DEV]
app-crypt/tpm2-tools: [PROD] [DEV]
app-crypt/tpm2-tss: [PROD] [DEV]
app-editors/nano:
app-emulation/qemu:
app-misc/jq: [PROD] [DEV]
app-portage/gentoolkit: [DEV]
dev-build/cmake:
dev-debug/strace: [PROD] [DEV]
dev-lang/go:
dev-lang/nasm:
dev-libs/json-c: [PROD] [DEV]
dev-libs/jsoncpp:
dev-libs/libgpg-error: [PROD] [DEV]
dev-libs/libxml2: [PROD] [DEV]
dev-libs/opensc:
dev-python/cryptography:
dev-python/cython:
dev-python/distlib: [SYSEXT-PYTHON]
dev-python/msgpack: [SYSEXT-PYTHON]
dev-python/setuptools-scm: [SYSEXT-PYTHON]
dev-python/snakeoil:
dev-python/typing-extensions: [SYSEXT-PYTHON]
dev-python/vcs-versioning: [SYSEXT-PYTHON]
dev-util/maturin:
dev-util/pkgcheck:
dev-util/xdelta: [SYSEXT-INCUS]
eclass/kernel-2.eclass:
eclass/selinux-policy-2.eclass:
net-dns/bind: [PROD] [DEV]
net-dns/c-ares: [PROD] [DEV]
net-fs/samba: [PROD] [DEV]
net-libs/nghttp2: [PROD] [DEV]
net-libs/ngtcp2: [PROD] [DEV]
net-misc/curl: [PROD] [DEV]
net-misc/socat: [PROD] [DEV]
net-misc/wget: [PROD] [DEV]
sec-policy/selinux-base-policy: [PROD] [DEV]
sys-apps/acl: [PROD] [DEV]
sys-apps/attr: [PROD] [DEV]
sys-apps/diffutils: [PROD] [DEV]
sys-apps/coreutils: [PROD] [DEV]
sys-apps/file: [DEV]
sys-apps/less: [PROD] [DEV]
sys-apps/pkgcore:
sys-apps/policycoreutils: [PROD] [DEV]
sys-apps/portage: [DEV]
sys-apps/sandbox: [DEV]
sys-apps/sed: [PROD] [DEV]
sys-apps/semodule-utils: [PROD] [DEV]
sys-apps/util-linux: [PROD] [DEV]
sys-auth/sssd: [PROD] [DEV]
sys-block/thin-provisioning-tools: [PROD] [DEV]
sys-fs/cryptsetup: [PROD] [DEV]
sys-fs/lvm2: [PROD] [DEV]
sys-fs/zfs: [SYSEXT-ZFS]
sys-libs/libnvme: [PROD] [DEV]
sys-libs/libseccomp: [PROD] [DEV]
sys-libs/libselinux: [PROD] [DEV]
sys-libs/libsemanage: [PROD] [DEV]
sys-libs/libsepol: [PROD] [DEV]
sys-libs/pam: [PROD] [DEV]
sys-process/audit: [PROD] [DEV]
sys-process/time:
--