Skip to content

Commit e446957

Browse files
authored
Merge pull request #1392 from flatcar/krnowak/dev-libs-automation
Put dev-libs packages under automation, move net-misc/ntp to portage-stable
2 parents 4bc44d7 + 8fe4636 commit e446957

File tree

119 files changed

+3185
-1631
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

119 files changed

+3185
-1631
lines changed

.github/workflows/portage-stable-packages-list

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -115,8 +115,8 @@ app-misc/mime-types
115115
app-misc/pax-utils
116116

117117
app-portage/elt-patches
118-
app-portage/portage-utils
119118
app-portage/gentoolkit
119+
app-portage/portage-utils
120120

121121
app-shells/bash
122122
app-shells/bash-completion
@@ -129,8 +129,6 @@ app-text/docbook-xsl-stylesheets
129129
app-text/manpager
130130
app-text/sgml-common
131131

132-
sec-keys/openpgp-keys-gentoo-release
133-
134132
dev-cpp/gtest
135133

136134
dev-db/sqlite
@@ -146,33 +144,49 @@ dev-lang/yasm
146144

147145
dev-libs/cJSON
148146
dev-libs/cyrus-sasl
147+
dev-libs/ding-libs
149148
dev-libs/elfutils
150149
dev-libs/expat
151150
dev-libs/glib
152151
dev-libs/gmp
153152
dev-libs/gobject-introspection
154153
dev-libs/gobject-introspection-common
155154
dev-libs/inih
155+
dev-libs/jansson
156+
dev-libs/json-c
156157
dev-libs/jsoncpp
157158
dev-libs/libaio
158159
dev-libs/libassuan
159160
dev-libs/libbsd
160161
dev-libs/libdnet
162+
dev-libs/libev
163+
dev-libs/libevent
164+
dev-libs/libffi
161165
dev-libs/libgcrypt
162166
dev-libs/libgpg-error
163167
dev-libs/libksba
168+
dev-libs/liblinear
164169
dev-libs/libltdl
165170
dev-libs/libmspack
166171
dev-libs/libnl
167172
dev-libs/libpcre
168173
dev-libs/libpcre2
169174
dev-libs/libpipeline
175+
dev-libs/libsodium
170176
dev-libs/libtasn1
177+
dev-libs/libunistring
171178
dev-libs/libusb
172179
dev-libs/libuv
180+
dev-libs/libverto
173181
dev-libs/libxml2
174182
dev-libs/libxslt
183+
dev-libs/libyaml
184+
dev-libs/lzo
185+
dev-libs/mpc
186+
dev-libs/mpfr
175187
dev-libs/nettle
188+
dev-libs/npth
189+
dev-libs/nspr
176190
dev-libs/oniguruma
177191
dev-libs/popt
178192
dev-libs/protobuf
@@ -355,6 +369,7 @@ net-misc/curl
355369
net-misc/ethertypes
356370
net-misc/iperf
357371
net-misc/iputils
372+
net-misc/ntp
358373
net-misc/rsync
359374
net-misc/socat
360375
net-misc/wget
@@ -373,14 +388,15 @@ profiles
373388
#
374389
# scripts
375390

391+
sec-keys/openpgp-keys-gentoo-release
392+
376393
sec-policy/selinux-base
377394
sec-policy/selinux-base-policy
378395
sec-policy/selinux-container
379396
sec-policy/selinux-dbus
380397
sec-policy/selinux-sssd
381398
sec-policy/selinux-unconfined
382399

383-
384400
sys-apps/acl
385401
sys-apps/attr
386402
sys-apps/bubblewrap
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
- ding-libs ([0.6.2](https://github.com/SSSD/ding-libs/releases/tag/0.6.2))
2+
- json-c ([0.17](https://github.com/json-c/json-c/blob/json-c-0.17-20230812/ChangeLog))
3+
- libffi ([3.4.4](https://github.com/libffi/libffi/releases/tag/v3.4.4) (includes [3.4.2](https://github.com/libffi/libffi/releases/tag/v3.4.2) and [3.4.3](https://github.com/libffi/libffi/releases/tag/v3.4.3)))
4+
- liblinear (246)
5+
- libsodium ([1.0.19](https://github.com/jedisct1/libsodium/releases/tag/1.0.19-RELEASE))
6+
- libunistring ([1.1](https://git.savannah.gnu.org/gitweb/?p=libunistring.git;a=blob;f=NEWS;h=5a43ddd7011d62a952733f6c0b7ad52aa4f385c7;hb=8006860b710aae2e8442088c3ddc7d819dfa8ac7))
7+
- mpc ([1.3.1](https://sympa.inria.fr/sympa/arc/mpc-discuss/2022-12/msg00049.html) (includes [1.3.0](https://sympa.inria.fr/sympa/arc/mpc-discuss/2022-12/msg00028.html))
8+
- mpfr ([4.2.1](https://gitlab.inria.fr/mpfr/mpfr/-/blob/4.2.1/NEWS))
9+
- nspr ([4.35](https://hg.mozilla.org/projects/nspr/log/b563bfc16c887c48b038b7b441fcc4e40a126d3b))
10+
- ntp ([4.2.8p17](https://www.ntp.org/support/securitynotice/4_2_8p17-release-announcement/))
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
[Service]
2+
Environment="SERVER=0.flatcar.pool.ntp.org 1.flatcar.pool.ntp.org 2.flatcar.pool.ntp.org 3.flatcar.pool.ntp.org"
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
# NOTES:
2+
# DHCP clients can append or replace NTP configuration files.
3+
# You should consult your DHCP client documentation about its
4+
# default behaviour and how to change it.
5+
6+
# Name of the servers ntpd should sync with
7+
# Please respect the access policy as stated by the responsible person.
8+
#server ntp.example.tld iburst
9+
10+
# Common pool for random people
11+
#server pool.ntp.org
12+
13+
# Pools for Flatcar users
14+
server 0.flatcar.pool.ntp.org
15+
server 1.flatcar.pool.ntp.org
16+
server 2.flatcar.pool.ntp.org
17+
server 3.flatcar.pool.ntp.org
18+
19+
##
20+
# A list of available servers can be found here:
21+
# http://www.pool.ntp.org/
22+
# http://www.pool.ntp.org/#use
23+
# A good way to get servers for your machine is:
24+
# netselect -s 3 pool.ntp.org
25+
##
26+
27+
# you should not need to modify the following paths
28+
driftfile /var/lib/ntp/ntp.drift
29+
30+
#server ntplocal.example.com prefer
31+
#server timeserver.example.org
32+
33+
# Warning: Using default NTP settings will leave your NTP
34+
# server accessible to all hosts on the Internet.
35+
36+
# If you want to deny all machines (including your own)
37+
# from accessing the NTP server, uncomment:
38+
#restrict default ignore
39+
40+
41+
# Default configuration:
42+
# - Allow only time queries, at a limited rate, sending KoD when in excess.
43+
# - Allow all local queries (IPv4, IPv6)
44+
# From commit da515112395ea7ce0da7cba7103de65d53fc93c9:
45+
#
46+
# net-misc/ntp: add notrap to default restrict config
47+
#
48+
# It's a common security hardening option and doesn't seem likely to
49+
# affect any actual usage.
50+
restrict default nomodify nopeer noquery notrap limited kod
51+
restrict 127.0.0.1
52+
restrict [::1]
53+
54+
55+
# To allow machines within your network to synchronize
56+
# their clocks with your server, but ensure they are
57+
# not allowed to configure the server or used as peers
58+
# to synchronize against, uncomment this line.
59+
#
60+
#restrict 192.168.0.0 mask 255.255.255.0 nomodify nopeer notrap
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
[Service]
2+
# From commit 5e5abb4d7ea48a9238b9baa22941fda6a6bbda8c:
3+
#
4+
# ntpd: always restart, required to handle large time jumps.
5+
#
6+
# Some VM platforms suspend machines by simply stopping them instead of
7+
# gracefully suspending them like real hardware would. This means that
8+
# when the system is resumed the kernel's time will be completely wrong
9+
# and it doesn't have a way to fix it. Additionally ntp will abort if the
10+
# clock offset is greater than 1000 seconds (conveniently without logging
11+
# any error messages). We can tune that in ntp.conf but ntpd has so many
12+
# knobs related to how it skews the clock and other update strategies that
13+
# the easiest option is to just restart.
14+
Restart=always

sdk_container/src/third_party/coreos-overlay/coreos-base/misc-files/misc-files-0-r2.ebuild renamed to sdk_container/src/third_party/coreos-overlay/coreos-base/misc-files/misc-files-0-r3.ebuild

Lines changed: 34 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ HOMEPAGE='https://www.flatcar.org/'
1212
LICENSE='Apache-2.0'
1313
SLOT='0'
1414
KEYWORDS='amd64 arm64'
15-
IUSE="openssh"
15+
IUSE="openssh ntp"
1616

1717
# No source directory.
1818
S="${WORKDIR}"
@@ -31,6 +31,7 @@ DEPEND="
3131
RDEPEND="
3232
${DEPEND}
3333
>=app-shells/bash-5.2_p15-r2
34+
ntp? ( >=net-misc/ntp-4.2.8_p17 )
3435
"
3536

3637
declare -A CORE_BASH_SYMLINKS
@@ -57,6 +58,24 @@ src_compile() {
5758
LC_ALL=C sort "${config_tmp}" >"${config}"
5859
}
5960

61+
misc_files_install_dropin() {
62+
local unit conf
63+
unit=${1}; shift
64+
conf=${1}; shift
65+
66+
[[ -n ${unit} ]] || die "No unit specified"
67+
[[ -n ${conf} ]] || die "No conf file specified"
68+
[[ ${conf} = *.conf ]] || die "Conf file must have .conf suffix"
69+
70+
local override_dir
71+
override_dir="$(systemd_get_systemunitdir)/${unit}.d"
72+
(
73+
insopts -m 0644
74+
insinto "${override_dir}"
75+
doins "${conf}"
76+
)
77+
}
78+
6079
src_install() {
6180
# Use absolute paths to be clear about what locations are used. The
6281
# dosym below will make relative paths out of them.
@@ -85,6 +104,11 @@ src_install() {
85104
['/usr/share/ssh/sshd_config']='/usr/share/flatcar/etc/ssh/sshd_config.d/50-flatcar-sshd.conf'
86105
)
87106
fi
107+
if use ntp; then
108+
compat_symlinks+=(
109+
['/usr/share/ntp/ntp.conf']='/usr/share/flatcar/etc/ntp.conf'
110+
)
111+
fi
88112

89113
local link target
90114
for link in "${!compat_symlinks[@]}"; do
@@ -133,16 +157,20 @@ src_install() {
133157

134158
# Install our socket drop-in file that disables the rate
135159
# limiting on the sshd socket.
136-
local override_dir
137-
override_dir="$(systemd_get_systemunitdir)/sshd.socket.d"
138-
dodir "${override_dir}"
139-
insinto "${override_dir}"
140-
doins "${FILESDIR}/no-trigger-limit-burst.conf"
160+
misc_files_install_dropin sshd.socket "${FILESDIR}/no-trigger-limit-burst.conf"
141161

142162
# Enable some sockets that aren't enabled by their own ebuilds.
143163
systemd_enable_service sockets.target sshd.socket
144164
fi
145165

166+
if use ntp; then
167+
insinto /etc
168+
doins "${FILESDIR}/ntp.conf"
169+
misc_files_install_dropin ntpd.service "${FILESDIR}/ntpd-always-restart.conf"
170+
misc_files_install_dropin ntpdate.service "${FILESDIR}/ntp-environment.conf"
171+
misc_files_install_dropin sntp.service "${FILESDIR}/ntp-environment.conf"
172+
fi
173+
146174
# Create a symlink for Kubernetes to redirect writes from /usr/libexec/... to /var/kubernetes/...
147175
# (The below keepdir will result in a tmpfiles entry in base_image_var.conf)
148176
keepdir /var/kubernetes/kubelet-plugins/volume/exec
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
# Do not install ntpdate or sntp systemd files in /etc.
2+
INSTALL_MASK+=" /etc/systemd"
3+
# Do not install the default ntp.conf, we provide our own in
4+
# coreos-base/misc-files.
5+
INSTALL_MASK+=" /etc/ntp.conf"
6+
# Do not install perl scripts to /usr/bin.
7+
INSTALL_MASK+=" /usr/bin/calc_tickadj /usr/bin/ntp-wait /usr/bin/ntptrace /usr/bin/update-leap"
8+
# Do not install perl package to /usr/share/ntp.
9+
INSTALL_MASK+=" /usr/share/ntp"

sdk_container/src/third_party/coreos-overlay/net-misc/ntp/files/ntp-4.2.8_p10-fix-build-wo-ssl-or-libressl.patch

Lines changed: 0 additions & 39 deletions
This file was deleted.

sdk_container/src/third_party/coreos-overlay/net-misc/ntp/files/ntp-4.2.8_p12-libressl-2.8.patch

Lines changed: 0 additions & 16 deletions
This file was deleted.

sdk_container/src/third_party/coreos-overlay/net-misc/ntp/files/ntp.conf

Lines changed: 0 additions & 19 deletions
This file was deleted.

0 commit comments

Comments
 (0)