summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* go-errors: update to 0.8.1Bruce Ashfield2021-09-161-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping go-errors to version v0.8.1-32-g5dd12d0, which comprises the following commits: 5dd12d0 AddingPowerSupport_CI/Testing (#234) 614d223 Revert "Support Go 1.13 error chains in `Cause` (#215)" (#220) 49f8f61 Support Go 1.13 error chains in `Cause` (#215) 004deef remove unnecessary use of fmt.Sprintf (#217) 6d954f5 feat: support std errors functions (#213) 7f95ac1 Add support for Go 1.13 error chains (#206) 91f1693 travis.yml: add Go 1.13 ca0248e fix travis, 1.10 doesnt support by unconvert anymore 27936f6 travis.yml: add Go 1.12 (#200) 856c240 Add json.Marshaler support to the Frame type. (#197) ffb6e22 Reduce allocations in StackTrace.Format (#194) e9933c1 Restore performance improvements from #150 ee1923e Return errors.Frame to a uintptr 72fa05e errors: detect unknown frames correctly (#192) c38ea53 Remove errors.Frame to runtime.Frame conversions (#189) c9e70be Makefile: switch to staticcheck (#187) ee4766c Fix error during merge 584cbac Remove checks for old style anon funcs (#186) 42ce1b6 Remove Frame methods (#185) 937e8c5 gofmt -w e19cb69 Remove last reference to runtime.FuncForPC (#184) 4f47277 Switch to runtime.CallersFrames (#183) 537896a travis: remove Go 1.8 and earlier (#182) 31aac83 travis: use Makefile (#181) 5ac96ae Update README.md ba968bf gofmt -w errors.go (#179) 059132a Update .travis.yml (#168) d58f942 Bump Travis versions (#172) 6ed0a2e Fix StackTrace print example 2233dee Copyedit the package documentation (#135) e981d1a Add WithMessagef function (#118) c059e47 fixed spelling (#156) 816c908 travis.yml: add Go 1.10 (#154) e1ac100 reduce allocations when printing stack traces (#149) 30136e2 Remove deadcode (#146) e881fd5 Fix minor typo in README.md (#142) 8842a6e Add badge for number of dependent libraries (#109) e4f5060 Fix doc comment for exported Format func (#137) f15c970 Remove an unused argument of utility test func (#139) 2b3a18b travis: add 1.9.x to go versions (#133) c605e28 Add doc comment for exported Format func (#115) ff09b13 Bump Go versions, use latest patch releases (#110) bfd5150 Move benchmark assigned err to global exported variable (#106) 248dadf Bump Go versions (#91) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* lxc: Enable seccomp support for lxcsana kazi2021-09-092-0/+48
| | | | | | | | | | | Enabled seccomp support for lxc. Also added a patch to enable seccomp.profile only when compiled with libseccomp. Currently, seccomp.profile is silently ignored. This could lead to the false impression that the seccomp filter is applied while it actually isn't. Signed-off-by: Sana Kazi <Sana.Kazi@kpit.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update to 3.3.1Bruce Ashfield2021-09-061-2/+2
| | | | | | | | | | | | | | | | | | | | | | Bumping libpod to version v3.3.1-2-g364efce39, which comprises the following commits: 1b33f7675 Bump to v3.3.2-dev 4c5283fab Bump to v3.3.1 bea109608 clean up socket and pid files from podman machine 68a059d89 Update release notes for v3.3.1 0103a0459 rootless cni: resolve absolute symlinks correctly 77948c8b4 Add filter params description to volume list/prune docs aa754c7e2 logFile until flag issue f363b805c Fix file descriptor leaks and add test d1ea54549 utils.RunUnderSystemdScope(): always close Conn 17afae4eb Use pod netns with --pod-id-file c16daa07e e2e tests: fix overlay: Unknown option vfs.imagestore 85846b633 change error comparison for exec.ErrNotFound 822818287 generate systemd: use --cidfile again 8aeaf681d Bump to v3.3.1-dev 98f252a3a Bump to v3.3.0 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* virtual/containerd: don't rprovide virtual/Bruce Ashfield2021-09-065-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Similar to the oe-core commit: commit 93ac180d8c389f16964bce8bd5538d9389e970e6 Author: Michael Opdenacker <michael.opdenacker@bootlin.com> Date: Wed Sep 1 11:20:20 2021 +0200 meta: stop using "virtual/" in RPROVIDES and RDEPENDS Fixes [YOCTO #14538] Recipes shouldn't use the "virtual/" string in RPROVIDES and RDEPENDS. That's confusing because "virtual/" has no special meaning in RPROVIDES and RDEPENDS (unlike in PROVIDES and DEPENDS). Instead, using "virtual-" instead of "virtual/" as already done in the glibc recipe. We stop rproviding virtual/containerd to keep the namespace clean. There aren't many users of this virtual provides, but we keep it around (for now) to maintain compatibility. At the same time we convert the RPROVIDES to virtual-containerd, to keep it available and consistent with oe-core use virtual-libc, etc. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* virtual/runc: don't rprovide virtual/Bruce Ashfield2021-09-066-6/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Similar to the oe-core commit: commit 93ac180d8c389f16964bce8bd5538d9389e970e6 Author: Michael Opdenacker <michael.opdenacker@bootlin.com> Date: Wed Sep 1 11:20:20 2021 +0200 meta: stop using "virtual/" in RPROVIDES and RDEPENDS Fixes [YOCTO #14538] Recipes shouldn't use the "virtual/" string in RPROVIDES and RDEPENDS. That's confusing because "virtual/" has no special meaning in RPROVIDES and RDEPENDS (unlike in PROVIDES and DEPENDS). Instead, using "virtual-" instead of "virtual/" as already done in the glibc recipe. We stop rproviding virtual/runc to keep the namespace clean. There aren't many users of this virtual provides, but we keep it around (for now) to maintain compatibility. At the same time we convert the RPROVIDES to virtual-runc, to keep it available and consistent with oe-core use virtual-libc, etc. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* libibverbs: don't rprovide virtual/libibverbsBruce Ashfield2021-09-061-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | Similar to the oe-core commit: commit 93ac180d8c389f16964bce8bd5538d9389e970e6 Author: Michael Opdenacker <michael.opdenacker@bootlin.com> Date: Wed Sep 1 11:20:20 2021 +0200 meta: stop using "virtual/" in RPROVIDES and RDEPENDS Fixes [YOCTO #14538] Recipes shouldn't use the "virtual/" string in RPROVIDES and RDEPENDS. That's confusing because "virtual/" has no special meaning in RPROVIDES and RDEPENDS (unlike in PROVIDES and DEPENDS). Instead, using "virtual-" instead of "virtual/" as already done in the glibc recipe. We stop rproviding virtual/libibverbs to keep the namespace clean. There aren't many (any) users of this virtual provides, but we keep it around (for now) to maintain compatibility. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xtf: add testimage integration to run XTF test cases in OEQAChristopher Clark2021-09-025-1/+150
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add a new minimal OEQA test case to run the Xen Test Framework test runner in the standard testimage step. Tested with qemux86-64 and designed for compatibility with Arm when XTF supports it. To enable, append to local.conf: INHERIT += "testimage" QEMU_USE_SLIRP = "1" TEST_SERVER_IP = "127.0.0.1" To run: bitbake -c testimage xtf-image For inspection while it runs, at another shell prompt: * Observe the image booting: tail -f ${TMPDIR}/work/qemux86_64-*/xtf-image/*/testimage/qemu_boot_log.* * Observe the tests running once boot has completed: tail -f ${TMPDIR}/work/qemux86_64-*/xtf-image/*/temp/log.do_testimage The XTF test sequence by default is a single XTF test case with minimal hardware dependency to ensure that Xen is running, the Xen toolstack is functional and XTF works. Additional XTF test cases for an image can be configured via variables that are documented in the OEQA test case: * XTF_TEST_CASES_POPULATE * XTF_TEST_CASES_SKIP * XTF_TEST_CASES_REQUIRE Since testimage requires a functioning network to perform the tests on the image and the qemu MACHINES do not have networking enabled this commit provides a new qemuboot-testimage-network bbclass to add an image postprocess command to enable a functional eth0 for qemu MACHINES. Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xtf-image: update qemuboot settingsChristopher Clark2021-09-021-5/+0
| | | | | | | | | | | | QB_MEM is now set via the qemuboot-xen-defaults bbclass and has the better default value of 512MB, which fixes some test failures observed when using the lower previous default value of 400MB. The SYSLINUX_XEN_ARGS method of setting the intended dom0 memory level did not take effect in practice, so remove it. Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xtf-image: fix QB_DEFAULT_FSTYPE: only needed for x86-64 qemuChristopher Clark2021-09-021-1/+1
| | | | | | | The qemuboot launch method for x86-64 uses wic but Arm does not. Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xen-image-minimal: supply bootloader config for qemux86-64 machineChristopher Clark2021-09-023-0/+21
| | | | | | | | | | | | | | | | Add a dedicated bootloader config for the qemux86-64 machine so that the 'pmtmr=0' kernel command line argument can be provided, which removes an error message that otherwise occurs in syslog during boot which is detected by an OEQA test case causing it to fail. A new kickstart file is provided that applies the new bootloader config and it is supplied as an override to WKS_FILE for this image. This is work towards enabling the Xen Test Framework (XTF) in the OEQA testimage framework. Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* python-cached: synchronize with meta-pythonBruce Ashfield2021-09-011-1/+3
| | | | | | | | | | | | | | | | | | | python3-cached-property was recently added to meta-python, with the same version, but slightly different variable definitions. This is breaking reprodicibility tests. We've had some issues with python packages upgrading in meta-python and causing runtime issues, so we temporarily want to hold onto a copy of this recipe until that can be ruled out. We'll either pin the version in meta-virt or remove the recipe once that is determined. But for now, if we synchronize the recipe variables, the reprodicibility checks should stop failing. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xen, xen-tools: apply workaround for gnu linker error to fix x86 buildChristopher Clark2021-08-277-0/+42
| | | | | | | | Upstream patch applied to each Xen and Xen tools recipe to fix the build of the hypervisor and shim with GNU linker 2.37. Signed-off-by: Christopher Clark <christopher.w.clark@gmail.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* busybox-initrd: rename to match 1.34.0 version from oe-coreMartin Jansa2021-08-271-0/+0
| | | | | | | | Upgraded in: https://git.openembedded.org/openembedded-core/commit/?id=d0e694ef4ec7bd862bdefee494210e3878152b44 Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cri-o: update to 1.22-devBruce Ashfield2021-08-271-2/+2
| | | | | | | Updating to the latest cri-o development branches to align with k*s testing and dev. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* containerd: update to v1.5.5Bruce Ashfield2021-08-271-2/+2
| | | | | | | | | | | | | | | Bumping containerd to version v1.5.5-11-g69e5db821, which comprises the following commits: 27e164648 Allow expanded DNS configuration 8cfab161f CI: Switch to available latest images b9d5cff5d Update Go to 1.16.7 fe195c343 mergo: Upgrade to 0.3.12 to fix panic 677fade0f Prepare release notes for v1.5.5 166a81f88 snapshot/devmapper: log exported methods correctly eb4ba99fe Install apparmor parser for arm64 environment 0bc1e1d8a update seccomp version Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-distrubution: update to 2.7-latestBruce Ashfield2021-08-271-1/+1
| | | | | | | | | | | | Not much of an update, but we pickup the latest compatibility restrictions: Bumping docker-distribution to version v2.7.1-32-g61e7e208, which comprises the following commits: d836b23f [release/2.7] update to go1.16 cc341b01 Added flag for user configurable cipher suites Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* runc-docker: update to 1.0.2Bruce Ashfield2021-08-271-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping runc to version v1.0.2-2-g04bcb7c7, which comprises the following commits: 86d83333 VERSION: back to development 52b36a2d VERSION: release 1.0.2 8ec57628 libct/cg/sd/v1: add SkipFreezeOnSet knob 1850dc16 libct/cg/sd/v1: add freezeBeforeSet unit test 4ce440f2 libct/cg/sd/v1: Fix unnecessary freeze/thaw 13b45cb4 libct/nsenter: fix unused-result warning 7cf1952f libct/nsenter: fix logging race in nsexec e2e5267c [1.0] script/release.sh: make builds reproducible 960182fd libct/seccomp: skip redundant rules 4c70105b libct/cg/v1: workaround CPU quota period set failure 1d454045 Do not use Vagrant for CentOS 7/8 c8d8fd5b tests/rootless.sh: fixup for "update rt" test 257018e7 tests/int: fix "update rt period and runtime" for rootless 76c047f1 Evaluate Cirrus CI for Vagrant tests 466d1a1a VERSION: back to development 4144b638 VERSION: release 1.0.1 4efb7a69 libct/cg/sd: add TestPodSkipDevicesUpdate 82d3eb69 libct/cg/sd: TestFreezePodCgroup: rm explicit freeze 2fc2e3d6 libct/cg/sd/v1: Set: avoid unnecessary freeze/thaw ef0aa849 libct/int/TestFreeze: test freeze/thaw via Set 01cd4b5f libct/int: allow subtests 22b2ff0f libct/cg/sd/v1: Set: don't overwrite r.Freezer 04edd79d libct/cg/sd: Don't freeze cgroup on cgroup v2 Set 298a3100 Update device update tests 257723b3 ci/gha: run on release-* branches after a push 4dc207a6 cgroupv2: ebpf: ignore inaccessible existing programs 90d01a04 vendor: update github.com/cilium/ebpf 3f40fbff libct/cg/sd: Add freezer tests c1a5b3e1 libct/cg/fs/freezer.GetState: report current cgroup state 0a5d8ba4 libct/user: fix parsing long /etc/group lines 5fd7b3b7 libct/user: ParseGroupFilter: use TrimSpace 0025bf68 libct/user: use []byte more, avoid allocations 3745b2be [1.0] retry unix.EINTR for container init process e99c0f5e tests/int/no_pivot: fix for new kernels 84113eef VERSION: release runc 1.0.0 29168172 tests/int/cgroups: add test for bfq per-device weight 1036f3f9 libct/cg/fs2: set per-device io weight if available 30d83d4d libct/cg/fs/blkio: do not set weight == 0 d7fc3028 libct/cg/fs*: mark {Open,Read,Write}File as deprecated 8f1b4d4a libct/cg: mv fscommon.{Open,Read,Write}File to cgroups 322c8fd3 Returns clearer error message for setenv 46940ed8 update cilium/ebpf to fix haveBpfProgReplace() check 6339d8a0 libcontainer/cgroups/fs/blkio: support BFQ weight[_device] 01f5dcae build(deps): bump tim-actions/get-pr-commits from 1.0.0 to 1.1.0 bd8e0701 libct/cg/sd: fix "SkipDevices" handling 1b2abc89 github: workflows: fix tiny typo b31a9340 libcontainer: relax validation for absolute paths dbb35411 configs/validator: move cgroup validation to the list of checks 9573e4b6 libct/cg/fs: don't forget to close a file 9ebc573a cgroupv2: ebpf: debug info when detaching programs in fallback mode a3ca7b47 cgroupv2: ebpf: check for BPF_F_REPLACE support and degrade gracefully d06bda60 libct/cg/sd/dbus: fix NewDbusConnManager 535f25c4 Allow restoring with a different LSM profile 508f5bf6 libct/int: add device update test 8fe3dfbb libcontainer/system: remove alias for deprecated RunningInUserNS 3f23a736 libcontainer/configs: remove stubs for deprecated Devices funcs b2d28c5d libct/cg/sd: fix dbus error handling bf7492ee runc update: skip devices c3831d64 libct/cg/fs/stats_util_test: use t.Helper 9eb0371b libct/cg/fs/memory_test: fix formatting e969d421 libct/int/testPids: logging nits a5bd78ef vendor: willf/bitset@v1.1.11 -> bits-and-blooms/bitset@v1.2.0 65cf0e61 Bump selinux to v1.8.2 f99d252d docs/terminals.md: add troubleshooting 49ea4b37 update crosbymichael email 3e1bcb1f libcontainer/keys: var should be sessKeyID/ringID (golint) 1fb56f9f libcontainer/cgroups/devices: if block ends with a return statement c2416fb4 libcontainer/system: fix godoc (golint) 9be156cb libcontainer/devices: fix godoc (golint) 340fdd93 libcontainer/nsenter: fix captalization (golint) 81fc5c87 libcontainer/user: fix capitalization (golint) e204d6a9 libcontainer/configs: add / fix godoc (golint) c0643046 libcontainer/apparmor: split api (exported) from implementation 02fb18ed libcontainer/user: remove unused ErrUnsupported 9e964dfc build(deps): bump github.com/opencontainers/selinux from 1.8.0 to 1.8.1 470610d0 build(deps): bump github.com/cilium/ebpf from 0.5.0 to 0.6.0 31f58829 build(deps): bump github.com/coreos/go-systemd/v22 from 22.3.1 to 22.3.2 c836265b build(deps): bump github.com/sirupsen/logrus from 1.7.0 to 1.8.1 074aa044 build(deps): bump google.golang.org/protobuf from 1.25.0 to 1.26.0 7ca54562 Enable dependabot e6048715 Use gofumpt to format code 1eea9253 cgroup2: io: add io.stats parsing test 0fef122f cgroup2: io: handle 64-bit values correctly on 32-bit architectures efca32c7 cgroup2: io: map io.stats to v1 blkio.stats correctly 49d293a5 cgroup2: capitalize io stats read and write Op values 0e16e7c2 libct/cg/sd: add SkipDevices unit test f5a2c9cc tests/int/dev: only call lsblk once aa934af0 runc -v: set default for, always show main.version 37767c05 ci: lint: show all errors in PRs 07ca0be0 *: clean up remaining golangci-lint failures 752e7a82 libct/cg/sd: fix SkipDevices for systemd fdc28957 Makefile: use git describe for $COMMIT 33c9f8b9 libct/cg/sd: return error from stopUnit Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* runc-opencontainers: update to v1.0.2Bruce Ashfield2021-08-272-13/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We refresh our patch context and pickup the following commits: Bumping runc to version v1.0.2-2-g04bcb7c7, which comprises the following commits: 86d83333 VERSION: back to development 52b36a2d VERSION: release 1.0.2 8ec57628 libct/cg/sd/v1: add SkipFreezeOnSet knob 1850dc16 libct/cg/sd/v1: add freezeBeforeSet unit test 4ce440f2 libct/cg/sd/v1: Fix unnecessary freeze/thaw 13b45cb4 libct/nsenter: fix unused-result warning 7cf1952f libct/nsenter: fix logging race in nsexec e2e5267c [1.0] script/release.sh: make builds reproducible 960182fd libct/seccomp: skip redundant rules 4c70105b libct/cg/v1: workaround CPU quota period set failure 1d454045 Do not use Vagrant for CentOS 7/8 c8d8fd5b tests/rootless.sh: fixup for "update rt" test 257018e7 tests/int: fix "update rt period and runtime" for rootless 76c047f1 Evaluate Cirrus CI for Vagrant tests 466d1a1a VERSION: back to development 4144b638 VERSION: release 1.0.1 4efb7a69 libct/cg/sd: add TestPodSkipDevicesUpdate 82d3eb69 libct/cg/sd: TestFreezePodCgroup: rm explicit freeze 2fc2e3d6 libct/cg/sd/v1: Set: avoid unnecessary freeze/thaw ef0aa849 libct/int/TestFreeze: test freeze/thaw via Set 01cd4b5f libct/int: allow subtests 22b2ff0f libct/cg/sd/v1: Set: don't overwrite r.Freezer 04edd79d libct/cg/sd: Don't freeze cgroup on cgroup v2 Set 298a3100 Update device update tests 257723b3 ci/gha: run on release-* branches after a push 4dc207a6 cgroupv2: ebpf: ignore inaccessible existing programs 90d01a04 vendor: update github.com/cilium/ebpf 3f40fbff libct/cg/sd: Add freezer tests c1a5b3e1 libct/cg/fs/freezer.GetState: report current cgroup state 0a5d8ba4 libct/user: fix parsing long /etc/group lines 5fd7b3b7 libct/user: ParseGroupFilter: use TrimSpace 0025bf68 libct/user: use []byte more, avoid allocations 3745b2be [1.0] retry unix.EINTR for container init process e99c0f5e tests/int/no_pivot: fix for new kernels 84113eef VERSION: release runc 1.0.0 29168172 tests/int/cgroups: add test for bfq per-device weight 1036f3f9 libct/cg/fs2: set per-device io weight if available 30d83d4d libct/cg/fs/blkio: do not set weight == 0 d7fc3028 libct/cg/fs*: mark {Open,Read,Write}File as deprecated 8f1b4d4a libct/cg: mv fscommon.{Open,Read,Write}File to cgroups 322c8fd3 Returns clearer error message for setenv 46940ed8 update cilium/ebpf to fix haveBpfProgReplace() check 6339d8a0 libcontainer/cgroups/fs/blkio: support BFQ weight[_device] 01f5dcae build(deps): bump tim-actions/get-pr-commits from 1.0.0 to 1.1.0 bd8e0701 libct/cg/sd: fix "SkipDevices" handling 1b2abc89 github: workflows: fix tiny typo b31a9340 libcontainer: relax validation for absolute paths dbb35411 configs/validator: move cgroup validation to the list of checks 9573e4b6 libct/cg/fs: don't forget to close a file 9ebc573a cgroupv2: ebpf: debug info when detaching programs in fallback mode a3ca7b47 cgroupv2: ebpf: check for BPF_F_REPLACE support and degrade gracefully d06bda60 libct/cg/sd/dbus: fix NewDbusConnManager 535f25c4 Allow restoring with a different LSM profile 508f5bf6 libct/int: add device update test 8fe3dfbb libcontainer/system: remove alias for deprecated RunningInUserNS 3f23a736 libcontainer/configs: remove stubs for deprecated Devices funcs b2d28c5d libct/cg/sd: fix dbus error handling bf7492ee runc update: skip devices c3831d64 libct/cg/fs/stats_util_test: use t.Helper 9eb0371b libct/cg/fs/memory_test: fix formatting e969d421 libct/int/testPids: logging nits a5bd78ef vendor: willf/bitset@v1.1.11 -> bits-and-blooms/bitset@v1.2.0 65cf0e61 Bump selinux to v1.8.2 f99d252d docs/terminals.md: add troubleshooting 49ea4b37 update crosbymichael email 3e1bcb1f libcontainer/keys: var should be sessKeyID/ringID (golint) 1fb56f9f libcontainer/cgroups/devices: if block ends with a return statement c2416fb4 libcontainer/system: fix godoc (golint) 9be156cb libcontainer/devices: fix godoc (golint) 340fdd93 libcontainer/nsenter: fix captalization (golint) 81fc5c87 libcontainer/user: fix capitalization (golint) e204d6a9 libcontainer/configs: add / fix godoc (golint) c0643046 libcontainer/apparmor: split api (exported) from implementation 02fb18ed libcontainer/user: remove unused ErrUnsupported 9e964dfc build(deps): bump github.com/opencontainers/selinux from 1.8.0 to 1.8.1 470610d0 build(deps): bump github.com/cilium/ebpf from 0.5.0 to 0.6.0 31f58829 build(deps): bump github.com/coreos/go-systemd/v22 from 22.3.1 to 22.3.2 c836265b build(deps): bump github.com/sirupsen/logrus from 1.7.0 to 1.8.1 074aa044 build(deps): bump google.golang.org/protobuf from 1.25.0 to 1.26.0 7ca54562 Enable dependabot e6048715 Use gofumpt to format code 1eea9253 cgroup2: io: add io.stats parsing test 0fef122f cgroup2: io: handle 64-bit values correctly on 32-bit architectures efca32c7 cgroup2: io: map io.stats to v1 blkio.stats correctly 49d293a5 cgroup2: capitalize io stats read and write Op values 0e16e7c2 libct/cg/sd: add SkipDevices unit test f5a2c9cc tests/int/dev: only call lsblk once aa934af0 runc -v: set default for, always show main.version 37767c05 ci: lint: show all errors in PRs 07ca0be0 *: clean up remaining golangci-lint failures 752e7a82 libct/cg/sd: fix SkipDevices for systemd fdc28957 Makefile: use git describe for $COMMIT 33c9f8b9 libct/cg/sd: return error from stopUnit Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* skoeo: update to 1.4.x release seriesBruce Ashfield2021-08-272-7/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | updating to the 1.4.x release series, we refresh our Makefile patch and pick up the following commits: 6b2aa5da [release-1.4] Bump to v1.4.2-dev 130f32f0 [release-1.4] Bump to v1.4.1 6f99811c [release-1.4] Bump c/image 5.15.2 c/storage 1.34.1 c/common 0.42.1 a9f5f10c [release-1.4] Bump c/storage 1.34.0, c/image 5.15.1 and c/common 0.43.0 a44da449 Release 1.4.0 3d9340c8 vendor-in-container: update to golang:1.16 961d5da7 Accept repositories on login/logout fb03e033 update c/common, c/image, c/storage d70ea890 Update on Building on Ubuntu ce6035b7 Add timeouts when waiting on OpenShift or the registry to start 3a8d3cb5 Add docs and bash completions aeb61f65 Add support for decompressing while copying to dir:// 76eb9bc9 Update to enabled containers/image version a1f9318e Fix two instances of unused err found by go-staticcheck d82c6621 Bump github.com/containers/storage from 1.32.6 to 1.33.0 f0c49b5c Multi-arch image build: Daily version-tag push 5e550664 CONTRIBUTING: small fixes to commands 726d982c Fix --tls-verify bb447f2f Test both imageOptions and imageDestOptions in TestTLSVerifyFlags 2a98df6b Split testing of --tls-verify into separate TestTLSVerifyFlags a6cf2f42 Add the --tls-verify option to (skopeo logout) 285a5cb6 Fix using images from rate-limited docker hub 02bacf57 Use Fedora container for doccheck ae0595c5 Man page validation: part 2 of 2 ec73ff3d docs: Adding info re container signatures e460b9aa [CI:DOCS] Multi-arch image workflow: Make steps generic ee054863 Update nix pin with `make nixpkgs` 2476e99c Cirrus: Freshen CI images 76103a6c Bump github.com/containers/common from 0.40.1 to 0.41.0 990908bf Bump github.com/containers/storage from 1.32.5 to 1.32.6 ede29c91 Remove an unnecessary break 75f0183e Remove an unnecessary Sprintf 7ace4265 Fix TestDockerRepositoryReferenceParser 3d4fb09f Remove unused code 4efeb71e Set cobra.Command.CompletionOption already in createApp a0ce5421 Bump version to v1.4.0-dev f80bf8a3 Revert "integration tests: disable `ls` for logs" c39b3dc2 CONTRIBUTING: update vendoring instructions 8eaf0329 disable `completion` command aeb75f38 Bump github.com/spf13/cobra from 1.2.0 to 1.2.1 83603a79 Bump github.com/spf13/cobra from 1.1.3 to 1.2.0 6d6c8b56 Update tests for removal of error and Error from error messages 09282bcf Fix some comments in man-page-checker 09ca3ba4 Improve the description of (skopeo list-tags) 22908fb3 Include the mandatory --output option in synopsis of (skopeo standalone-sign) a3725128 Support **non-replaceable strings** in synopsis e4d13920 Use (make validate-local) in the validate target e716b2fa man page checker - part 1 of 2 97eaace7 Cirrus: Rename cross -> osx task, add cross task. 30c0eb03 Bump github.com/containers/ocicrypt from 1.1.1 to 1.1.2 5918513e Cirrus: Add vendor + tree status check b20c2d45 Run unit tests as well, not integration tests twice d0f7339b Bump github.com/containers/storage from 1.32.4 to 1.32.5 012ed661 Reintroduce the GNU semantics of DESTDIR c30b904c Add --retry-times to markdown docs 9fbb9abc Workaround quay.io image build failure 4417dc44 Update brew to avoid 403 on accessing https://homebrew.bintray.com 93b819a7 Fix automation re: master->main rename e7c5e9f7 Bump github.com/containers/storage from 1.32.3 to 1.32.4 1eac38e3 Bump github.com/containers/common from 0.40.0 to 0.40.1 b1e78efa Bump github.com/containers/storage from 1.32.2 to 1.32.3 298f7476 Bump github.com/containers/image/v5 from 5.13.1 to 5.13.2 5778d9bd Fix documentation of the --format option of skopeo copy and skopeo sync df170047 Bump github.com/containers/common from 0.39.0 to 0.40.0 ad4ec8b4 Cirrus: New VM Images w/ podman 3.2.1 abdc4a7e Bump github.com/containers/image/v5 from 5.12.0 to 5.13.1 bcc18ebf Update nix pin with `make nixpkgs` 9b9ef675 Fix multi-arch build version check 9a5f009e [CI:DOCS] Fix docs links due to branch rename 865407ca Bump github.com/containers/storage from 1.32.1 to 1.32.2 10c4c877 Update nix pin with `make nixpkgs` e32f3f17 Bump github.com/docker/docker 76110014 Fix wrong directory name a0b6ea28 Support [CI:DOCS] mode e5cb7ce1 install.md Building Docs needs MacOS section c8060838 Bump github.com/containers/storage from 1.32.0 to 1.32.1 cac3f2b1 Bump github.com/containers/common from 0.38.4 to 0.39.0 6452a9b6 Multi-arch github-action workflow unification 184f0eee Bump github.com/containers/storage from 1.31.1 to 1.31.2 65ed9920 Move to v1.3.1-dev Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* crun: update to 0.21-latestBruce Ashfield2021-08-271-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | Bumping crun to version 0.21-15-g360f5d0, which comprises the following commits: 2199d10 tests: update containerd version 1798d5a cgroup: chown cgroup to root b5cdeb5 cgroupv1: add support for setting memory.use_hierarchy 7cfdf09 Makefile.am: link libcrun to $(FOUND_LIBS) d4d1825 linux: treat pidfd_open EINVAL as ESRCH 62149b3 Update nixpkgs ac00581 Dockerfile: delete file c4c3cdf NEWS: release 0.21 69bd7dc Doc: cgroups v2 and RT processes unsupported 6397998 krun/kvm: crun should silently/gracefully switch to krun when needed. 92499bd container: wrap execv in retry-on-eintr b04a335 cgroup: lookup pids controller as well 448494e README.md: drop travis badge 1bbf562 Reflect #696 in crun's manpage e836219 rpm: fix license 2b88faa status: add fields for owner and created timestamp b07c389 criu: fix error check 09401bb linux: fix unitialized variable b222968 cgroup: fix a memory leak Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-ce: update to 20.10.8Bruce Ashfield2021-08-271-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | Bumping docker-cli to version v20.10.8-2-g62eae52c2, which comprises the following commits: 2012fbf11 Update Go to 1.16.7 0b924e51f Update to go1.16.6 6288e8b1a change TestNewAPIClientFromFlagsWithHttpProxyEnv to an e2e test 1e9575e81 cli/config/configfile: various test cleanups c98e9c47c Use designated test domains (RFC2606) in tests 8437cfefa context: deprecate support for encrypted TLS private keys 68a5ca859 cli/context: ignore linting warnings about RFC 1423 encryption 8a6473963 Update Dockerfiles to latest syntax, remove "experimental" 1d37fb302 Deprecate Kubernetes context support 0793f9639 Deprecate Kubernetes stack support b639ea8b8 Deprecate Kubernetes stack support Bumping docker to version v20.10.8-2-gd24c6dc5cf, which comprises the following commits: decb56ac89 Update Go to 1.16.7 e8fb8f7acd [20.10] update containerd binary to v1.4.9 4cfeb27f78 update runc binary to v1.0.1 067918a8c3 [20.10] update containerd binary v1.4.8 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker/moby: update to 20.10.8Bruce Ashfield2021-08-271-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | Bumping docker-cli to version v20.10.8-2-g62eae52c2, which comprises the following commits: 2012fbf11 Update Go to 1.16.7 0b924e51f Update to go1.16.6 6288e8b1a change TestNewAPIClientFromFlagsWithHttpProxyEnv to an e2e test 1e9575e81 cli/config/configfile: various test cleanups c98e9c47c Use designated test domains (RFC2606) in tests 8437cfefa context: deprecate support for encrypted TLS private keys 68a5ca859 cli/context: ignore linting warnings about RFC 1423 encryption 8a6473963 Update Dockerfiles to latest syntax, remove "experimental" 1d37fb302 Deprecate Kubernetes context support 0793f9639 Deprecate Kubernetes stack support b639ea8b8 Deprecate Kubernetes stack support Bumping moby to version v20.10.8-2-gd24c6dc5cf, which comprises the following commits: decb56ac89 Update Go to 1.16.7 e8fb8f7acd [20.10] update containerd binary to v1.4.9 4cfeb27f78 update runc binary to v1.0.1 067918a8c3 [20.10] update containerd binary v1.4.8 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* k3s: update to 1.21.4Bruce Ashfield2021-08-271-2/+2
| | | | | | | | | | | | | | | | | | Bumping k3s to version v1.21.4+k3s1-1-g656c190629, which comprises the following commits: 656c190629 Reset load balancer state during restoraion (#3878) 3e250fdbab Update Kubernetes to v1.21.4-k3s1 5802b429f8 Bump containerd to v1.4.9-k3s1 abb6581a94 Bump helm-controller to work around tiller crashes e45726f610 Fix URL pruning when joining an etcd member 18bc38d838 account for an s3 folder when listing objects (#3807) (#3812) 12ec437605 fix Node stuck at deletion (#3775) 69047a35c0 Bump helm-controller to v0.10.2 cc694b1f09 Notify systemd for etcd only node (#3733) e6247d583c [Backport 1.21] Cannot write data to local PVC (#3721) 786f91b997 Fix multiple bootstrap keys found Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update to 3.3.0Bruce Ashfield2021-08-271-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping libpod to version v3.3.0-2-g8809aed56, which comprises the following commits: 8aeaf681d Bump to v3.3.1-dev 98f252a3a Bump to v3.3.0 2408247f4 Final release notes for v3.3.0 dd3a49703 Fix network aliases with network id b5e04ae11 machine: compute sha256 as we read the image file a52b6bf23 machine: check for file exists instead of listing directory b71ef443a pkg/bindings/images.nTar(): slashify hdr.Name values f0d0c48d2 Volumes: Only remove from DB if plugin removal succeeds 89818f72b For compatibility, ignore Content-Type 7fb7f15af [v3.3] Bump c/image 5.15.2, buildah v1.22.3 5fc7c880a Implement SD-NOTIFY proxy in conmon 15fff7d91 Fix rootless cni dns without systemd stub resolver 63e06acfe fix rootlessport flake a92441e1b Skip stats test in CGv1 container environments 37b22af33 Fix AVC denials in tests of volume mounts daa311db3 Restore buildah-bud test requiring new images 2757d868c Revert ".cirrus.yml: use fresh images for all VMs" cd0677d89 Fix device tests using ls test files ce7ed3359 Enhance priv. dev. check 1d54315b6 Workaround host availability of /dev/kvm c0d0d31c4 Skip cgroup-parent test due to frequent flakes 0c7f08805 Cirrus: Fix not uploading logformatter html a098eafce Bump to v3.3.0-dev 7aa18e0a6 Bump to v3.3.0-RC3 e200b07f5 Release notes for v3.3.0-RC3 204ac5d46 [v3.3] Bump c/storage to v1.34.1 and c/image to v5.15.1 440188f3b fix gvproxy path search for macos de67e990e Bump to v3.3.0-dev 88559c197 Bump to v3.3.0-rc2 1acbdf940 Set gvproxy path to /usr/libexec/podman/gvproxy 7442f0b85 Revert "Podman Pod Create --cpus and --cpuset-cpus flags" 61a5e9812 Address review comments e63753afd Final release notes for v3.3.0-RC2 f9f315c75 Document source ip for the rootlesskit port handler 66c0024a0 podman info show correct slirp4netns path d746a7e09 show podman machine ssh command line 4b42265b5 Fix TS parsing for fractional values 85d5c24ed Handle timezone on server containers.conf 67bf11e8c Fix podman unpause,pause,kill --all to work like podman stop --all a1afb2300 Do not add an entry to /etc/hosts with `--net=host` a82006160 Only support containers stats using cgroups v2 c836ffe5b Compat API: Fix healthcheck status and healthcheck config 04e59f11d podman info: try qfile before equery 870576b39 test: move container process to a sub-cgroup cb7f0a302 Fix handling of user specified container labels d749770fe Release notes for v3.3.0-RC2: Initial 0c82c6fa8 Bump github.com/rootless-containers/rootlesskit from 0.14.3 to 0.14.4 0eec16ce9 fix rootless port forwarding with network dis-/connect 50c6cc229 [v3.3] Bump to Buildah v1.22.0 [NO TESTS NEEDED] b1c9c5b5f Disable aarch64 support 489e0f075 Cirrus: CI Support for v3.3 Branch b347a3583 Bump to v3.3.0-dev ce0dee984 Bump to v3.3.0-rc1 c1156d48b Bump github.com/containers/storage from 1.33.0 to 1.33.1 58672847e Bump github.com/containers/image/v5 from 5.14.0 to 5.15.0 9d33abac6 Fix auto-update system test for older systemd 2a484e782 ps: support the container notation for ps --filter network=... 732ece6ae Add `--accept-repositories` integration tests d59391c04 system tests: fix race in stop test 2b5d9cd7d Fix: healthcheck tests use .Should() instead of .To() 872c442e6 Remove ReadHeaderTimeout 724d04823 rootless: avoid zombie process on first launch 1d34a2c4c Update transfer.md ec9dad7e4 buildah bud tests under podman-remote a9f6592af Fixed Healthcheck formatting, string to []string 4df6e31cc remote build: fix streaming and error handling e3b0ba928 [CI:DOCS] Update podman-cp manpage 013267006 cp: consolidate and simplify 67d439197 rootless: check that / is mounted as shared 32b589216 Multi-arch image build: Daily version-tag push 60b9e8c0d Added tests for out of and into pod checkpoint and restore support eb9446778 Support checkpoint/restore with pods 3375cbb19 Vendor in go-criu v5.1.0 for Pod checkpoint/restore support 92dce3e2f Prepare CRIU version check to work with multiple versions b09073832 Bump github.com/containers/storage from 1.32.6 to 1.33.0 0aec93edc cp system tests: reduce number of exec's 6fe03b25a support container to container copy 63ef5576e command: migrate doesn't move process to cgroup a0313ef92 rootless: do not overwrite err variable 7689783ae exec: fix cleanup fd1f57b3a Fixed Healthcheck formatting, string to []string 7fa4d2cb1 Add prune until filter test for podman volume cli 8d5d5face dual-stack network: fix duplicated subnet assignment 5473490c6 fix: podman manifest push respect --tls-verify flag c197d19fe play kube: support capitalized pull policy 1b6423e9f refine dangling checks 23a938fa2 Bump github.com/containers/image/v5 from 5.13.2 to 5.14.0 1a188f622 Add tests to verify CORS is enabled 2c9f18100 Fix handling of shadow-utils dcb5c92c0 import: write stdin to tmp file 8f9d33b7f Networking test: fix silent breakage 0f708efd8 Implemented --until flag for libpod's container logs 9c659b3bc docs: fix broken remote client link 2d8e837a9 Add until filter to volume ls filters list 12f4b14a1 Add notes to flags not supported on cgroups V2 3e79296a8 Support DeviceCgroupRules to actually get added. 4376f14c3 Ensure journald events tests only run where supported ac588c751 [CI:DOCS] Fix GitHub URL to Podman logo db2f47428 Drop podman create --storage-opt container flag 595227095 e2e tests: prevent 'Expect(ExitCode())' pattern 064bd9d19 Copy the content from the underlying image into the newly created volume. Fixes: #10262 313c7118e system tests: cleaner, safer use of systemd e64545004 [CI:DOCS] Multi-arch image workflow: Make steps generic 2b98a226b system test: auto-update: multiarch fixes caf03fd7a system test: auto-update: allow running as rootless 117850e6e Fix handling of selinux labels in podman play kube 6430c1316 [CI:DOCS] refine the runlabel man page eaaca4999 compat: image create: handle platform correctly 80e807a19 Flake Fix: Wait before connecting container port c622c7f2a (minor) typo fix: timeout variable 0784a5d04 Bump github.com/opencontainers/runc from 1.0.0 to 1.0.1 b92bbfd76 Just restore protections of shadow-utils 81e32b180 Kube: Add liveness probe for containers. b8accad0e Update Release Notes and README for 3.2.3 50fcb06e7 Bump k8s.io/api from 0.21.2 to 0.21.3 2e02942d4 vendor containers/common@main 6f1c7a0b6 systemd: require network*-online*.target e1ac0c303 vendor containers/common@main e3a09c51e Bump k8s.io/apimachinery from 0.21.2 to 0.21.3 be51173ed APIv2 (python) tests: fix flake 9924c57d4 podman start: remove containers configured for auto removal af40dfc2b --infra-name command line argument 7996e2b82 Randomize the auto-update of podman containers e4dcb1004 System tests: fix a multiarch problem ec6150751 Correct a typo in documentation f7321681d podman pod create --pid flag 0007c98dd Fix race conditions in rootless cni setup 547fff270 e2e tests: use Should(Exit()) and ExitWithError() 59f31d86a auto-update: add --dry-run e73d48299 CNI-in-slirp4netns: fix bind-mount for /run/systemd/resolve/stub-resolv.conf c9970647b podman-remote build use .containerignore over .dockerignore 100c23dc5 Fix up documentation of the userns audit flag 48e6a8eed Return macvlan object in /network REST API response Fixes: #10266 6ced24d0b Fix broken volume and container tests 01cfb51fe auto-update: make output more user friendly 92c9def93 Update nix pin with `make nixpkgs` cbbb1a80f Perform a one-sided close of HTTP attach conn on EOF 7d6f3c4dc Bump github.com/google/uuid from 1.2.0 to 1.3.0 6fcf0b2f3 auto update: minor style nits a90a4ec7c auto update: pass through a context a8847c01f auto-update: use libimage for image checks eda8d1f58 auto update: fix authfile detection db26e1ef9 auto-update: make restarted unit more obvious 6ca574dc3 Update USE in order to fix tests fe044d51e Fix cirrus-cron failure notification GH workflow 6cac65c84 fix: uid/gid for volume mounted to existing dir 084dbeb56 Bump github.com/containers/storage from 1.32.5 to 1.32.6 00db5c6ea Manifest create subcommand should accept more than 2 arguments 48ff2ef5a Don't exclude Dockerfile, Containerfiles from tar content 6bdb990c9 Restore headers of optional information in 'podman pod ps' 4624142c2 Implemented Until Query Parameter for Containers/logs a2d15d981 Mention new hostname for loopback IP daebdf385 Add container config to compat image inspect 00ed696ed fix: logo not loading after barnch renaming 95c463785 Update docs/tutorials/rootless_tutorial.md: e5fcffc55 Remove GetStore function from Libpod 563532aef Bump github.com/onsi/gomega from 1.13.0 to 1.14.0 38863e764 Replace old RESTful tutorial with updated README 38bef70b3 manifest push --rm: use libimage for removal 2c7c67958 Make rootless-cni setup more robust 518457b35 Bump github.com/cyphar/filepath-securejoin from 0.2.2 to 0.2.3 59abb77fc multiple image pull support 4ea4a92c0 Fixed notation for macOS 0c9dc86de Create podman temp dir on machine start ed51e3f54 podman service reaper 84da70a0f update shell completion scripts 924cd37a3 Bump github.com/spf13/cobra to v1.2.1 8f6a0243f podman diff accept two images or containers 735be1248 force github.com/spf13/cobra@v1.1.3 7eb9ed975 vendor containers/common@main 8606ead91 [CI:DOCS] podman search: clarify that results depend on implementation 493786fba podman: ignore ESRCH from kill 86c601414 Implement --archive flag for podman cp 092902b45 Handle advanced --network options in podman play kube 40ef17ac2 Cirrus: Fixes due to master->main rename 8b52204ba vendor containers/common@7482cf851dcc 2243b6020 reset: remove external containers on podman system reset 2ce78aace Enhance system connection add URL input 6d37e0348 Add CNI rootless networking troubleshooting for v2.2.1 05f39af5b Bump github.com/containers/storage from 1.32.3 to 1.32.5 3e8c0e00d Make system connection ls deterministic fb5f70296 Bump github.com/containers/ocicrypt from 1.1.1 to 1.1.2 1edada477 Makefile: remove install.cni 3d0e08f04 prefix `ETCDIR` with `${PREFIX}/` f95b0995e remove `pkg/registries` e7507fe7c make DriverOpts name consistent. a7a701196 fix: swapped volume relabel option values 364e8a26d pkg/systemd: don't require LISTEN_FDNAMES for socket activation b39aacf32 add @mtrmac to OWNERS b1082696e cp: do not allow dir->file copying ee7a9d736 [NO TESTS NEEDED] suggestions for incorrect cmds b56b4b537 read secret config from config file if no user data. 15fbf950e [CI:DOCS] podman save: clarify formats and transports 9db534e53 [NO TESTS NEEDED] Create /etc/mtab with the correct ownership 7d83f9b6c [CI:DOCS] Follow-up to PR 10676 bbd085ad1 Podman Pod Create --cpus and --cpuset-cpus flags 6ecdf4c38 Health Check is not handled in the compat LibpodToContainerJSON f2dff41db Support log_tag defaults from containers.conf 525cb54e1 [CI:DOCS] push/pull docs: clarify supported transports 5fc622f94 create: support images with invalid platform f26fa5392 Podman Stats additional features 1aa9dcfad markdown/*: typos 'a image' d12027e0d disable tty-size exec checks in system tests a0b24de32 Add support for volume prune until filter to http api 1f388ede6 Add --format to connection list a84fa194b getContainerNetworkInfo: lock netNsCtr before sync e01460853 Do not use inotify for OCICNI 7f98d2ddb docs: podman-rmi removes dangling parent images ee4cab0e0 logs: k8s-file: restore poll sleep f4ba433b1 logs: k8s-file: fix spurious error logs 0fb165ed0 Fix systemd-resolved detection. 9cc3473b5 Bump k8s.io/api from 0.21.1 to 0.21.2 1e36be439 Add support for podman login --verbose 7864108ff fix systemcontext to use correct TMPDIR 9a02b5055 Add an entry for `/run/user-$UID/libpod` to tmpfiles b56d6c646 Bump github.com/containers/storage from 1.32.2 to 1.32.3 d39823085 Bump k8s.io/apimachinery from 0.21.1 to 0.21.2 2bd382c8c Fix documentation of the --format option of podman push b6662eed3 Vendor in containers/common v0.40.0 bd9987239 Scrub podman commands to use report package 6b230bc92 Fix multi-arch image build clone:failure 705b799af Cirrus: Prevent BZ1965743 workaround pruning e344a5899 [CI:DOCS] UPDATE manpages with MANPAGE_SYNTAX 666f555aa Fix resize race with podman exec -it 404d5edb1 .cirrus.yml: use c5521575421149184 for Ubuntu 769df3207 test: drop invalid test 969cc3237 utils: move message from warning to debug 517479731 utils: improve error message eb927dc84 Docs Switch from Query Param to Header 9c81b8cf7 add correct slirp ip to /etc/hosts fc9868e22 Fix panic condition in cgroups.getAvailableControllers 2a974e8b9 Create user storage dir with correct permissions 5f2c0f63a Fix building static podman-remote 81eb71fe3 Fix permissions on initially created named volumes 3ddadc532 Image import fromSrc now supports OS/Arch 302b3084e Restart all containers with restart-policy=always on boot e8006c797 Fix handling of podman-remote build --device 4bca1984a UPDATE manpages with MANPAGE_SYNTAX 8d860cfcd podman-run.1.md:detach-keys: spell the default value just once ded2f004f Fall back to string for dockerfile parameter 44d9c453d Fix network connect race with docker-compose ad3b56c62 Fix volumes with uid and gid options 3a65ba2fa Add support for podman remote build -f - . 991647c77 Add documentation on ignore_chown_errors 40d70334e System tests: the continuing multiarch saga 62f4b0a19 Add ExecDied event and use it to retrieve exit codes 341e6a162 Always spawn a cleanup process with exec 4a4fe48cc Fix docs links due to branch rename 240bbc3bf Fix pre-checkpointing 3b6cb8fab container: ignore named hierarchies d9a1c34e4 Fix restoring of privileged containers c3a14103f Fix build tags for pkg/machine... b5890fc86 Bump github.com/containers/storage from 1.32.1 to 1.32.2 e7e09bf2f Update nix pin with `make nixpkgs` d5527c330 System tests: deal with crun 0.20.1 11badab04 rootless: fix fast join userns path 8e89d7071 [CI:DOCS] Update swagger for inspect network a9cb82498 podman-remote build should handle -f option properly 5117deda0 fixed docs and schemas 18fa124df Improve systemd-resolved detection 84b55eec2 logs: k8s-file: fix race a5ad36c65 Fix image prune --filter cmd behavior 346c7fda6 Bump github.com/containers/buildah from 1.21.0 to 1.21.1 c60548279 remote pull: cancel pull when connection is closed 8378a9c4d Fix network prune api docs 5e7876089 auto-update tests: various fixes f6d9dbb62 [CI:DOCS]instructions for podman machine on macs 260192670 Fix compat create with NetworkMode=default 17193e468 System test: Add podman auto-update related test cases a2b842df4 Version bump: 3.3.0-dev 949374e58 Added tests for different checkpoint archive compressions 68070f1b2 Add --compress to podman-container-checkpoint.1.md 8aa5340ad Add parameter to specify checkpoint archive compression 10875a67e Order checkpoint options in man page alphabetically ab7e7f651 UPDATE MANPAGE_SYNTAX (commit,attach,auto-update) 13a807b86 fix go-bindings examples with v3 new parameters 8f89bc4e0 [CI:DOCS] Document which CNI fields are encoded 1f73374ac remote: always send resize before the container starts 9c5048544 remote events: support labels ce01b4f09 made requested changes, fixed api tests 2810c478a Add CORS support df7c3a703 [CI:DOCS] fix incorrect network remove api doc e23c5b25f Add restore --publish to the man page 837ba7ec3 Add test for restore --publish 1ac9198d7 Allow changing of port forward rules on restore 86610c785 remote events: fix --stream=false 9ac526759 systemd/generate: change type to notify 346c08225 Update main branch to reflect 3.2.0 release b928278e6 extend docs to include help for when pub/priv key is signed with an unsupported algo 735470ff2 Bump go.etcd.io/bbolt from 1.3.5 to 1.3.6 48ea142ca Bump github.com/docker/docker b36278c3e Bump github.com/opencontainers/selinux from 1.8.1 to 1.8.2 df2e7e00f add ipv6 nameservers only when the container has ipv6 enabled 366016fa8 Bump github.com/onsi/ginkgo from 1.16.3 to 1.16.4 433a5a8c7 Fix spacing in buildthedocs 37f39eefe events: support disjunctive filters b6167cedb System tests: add :Z to volume mounts ff79b2e5a Fix link error 433674918 Use secrets and machine rst file properly 2cc4535e1 added tests in python rest api 7ef3981ab Enable port forwarding on host ad182976b Use request context instead of background 1daaf34d7 [NO TESTS NEEDED] API list networks should return [] when used with no networks 249da1b93 [CI:DOCS] rm containers-mounts.conf.5.md ef8ba99ff Use request context instead of background context 3330f9876 Better error handing for images/create compat api d657a070d Bump github.com/uber/jaeger-client-go 761466dca Bump github.com/onsi/ginkgo from 1.16.2 to 1.16.3 fb4a0c572 support tag@digest notation 530721841 generate systemd: make mounts portable 699272ed2 add missing space 51a8e01f8 [CI:DOCS] point IRC to libera.chat 2addc0f90 rootless: fix SIGSEGV ,make LISTEN_FDNAMES optional [Closes #10435]. [NO TESTS NEEDED] 5bd1b7dfd Update a way out of date transfer document 6deb1bc2a Manpage syntax proposal 33944cefe [Techinal Debt] Cleanup ABI vs. Tunnel CLI commands c9609d820 Vendor in containers/storage v1.32.1 9822c3309 create libimage-events channel in main routine 8e5388e41 Add options to podman machine ssh 61167834f Bump github.com/onsi/gomega from 1.12.0 to 1.13.0 de293c980 Handle image user and exposed ports in podman play kube fad6e1d3e Ensure that container still exists when removing 533d88b65 Add the option of Rootless CNI networking by default 10569c988 journald logger: fix race condition d1c9e034f libimage-events channel: fix data race 568e911b8 Bump github.com/containers/common from 0.38.4 to 0.39.0 738a8fe63 Add podman run --gpus flag for compatibility e6a3d6aac Fix race on podman start --all 9ab3fd876 Fix race condition in running ls container in a pod 586af5c74 docs: --cert-dir: point to containers-certs.d(5) afe33573d Handle hard links in different directories 2f5552c32 Podman info add support for status of cgroup controllers f22791aec Handle hard links in remote builds 4c095aa7e Improve OCI Runtime error 3c82059c3 Sync. workflow across skopeo, buildah, and podman 8bf852d5f Match swagger to "as built" output 0766777d6 Document all transports for podman manifest add 6ca721ccc Drop container does not exist on removal to debugf 94665bdf0 Bump github.com/containers/storage from 1.31.1 to 1.31.2 7bcfae44b Downgrade API service routing table logging c553181fd Vendor in containers/buildah v1.21.0 5a0257d46 Fix network create macvlan with subnet option 8352e5bc3 add libimage events 26652111b Bump github.com/opencontainers/runc from 1.0.0-rc94 to 1.0.0-rc95 12aa71ab8 Use correct extension for example network config 898a8ad28 update c/common 2b89b2414 Add support for podman manifest rm command 55f00bac0 Clear the storage-options from the graphdriver if users specifies --root 44c493717 Bump k8s.io/api from 0.21.0 to 0.21.1 bc0e12a04 Fix problem copying files when container is in host pid namespace 379df7f2c docs: generate systemd: XDG_RUNTIME_DIR af748b94e Bump k8s.io/apimachinery from 0.21.0 to 0.21.1 6b187e445 Bump github.com/vbauerster/mpb/v6 from 6.0.3 to 6.0.4 92e858914 fix: response body of containers wait endpoint 98955bedb Break up python APIv2 tests 8f3605e7d Add script for identifying commits in release branches bab7caafe Fix formatting and indentation in network http api docs cf30f160a Support uid,gid,mode options for secrets 0d811b233 Several shell completion fixes 6efca0bba Ensure that :Z/:z/:U can be used with named volumes 4cc19f9e0 Support automatic labeling of kube volumes b75bb4665 Create the /etc/mtab file if does not exists Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* kubernetes: update to 1.23-alpha latestBruce Ashfield2021-08-271-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping kubernetes to version v1.23.0-alpha.1-58-gf6331c74b67, which comprises the following commits: 6616655b7b6 create common interface for controllers. c1284118156 fix typo: Modify PodTrackingWithFinalizers to JobTrackingWithFinalizers 6dfae64d9be REST: Document mutable inputs on Create() 42c7e621804 Fix registry tests to look at result objects 75dea6b8bc2 Service REST: Use DeepCopy() on Create() and fix tests 322bc827771 Fix buffered signal channel go vet error 183498a410c Adds CancelRequest function to CommandHeadersRoundTripper bdedd2a4c16 apiserver: add key/value pair to httplog 3a660b72941 bump e2e loadbalancer timeouts to 15m 2c73d7834ac update vendor e1e4408ab34 allow k8s.io/utils/net imports 0cd75e8fec6 run hack/update-netparse-cve.sh e9ddac5d853 rename net.ParseCIDR on messages to avoid false positives 06f2d678eec update and verify netparse c2532351525 vendor: bump k8s.io/util to get fix for LRU cache 21491aa5a1a Bump livenessprobe to 2.4.0 in e2e hostpath driver spec 0af1c83e035 CHANGELOG: Update directory for v1.22.1 release b1a6f8cdf90 kubectl proxy: append context host path to request path 950c4dafecb CHANGELOG: Update directory for v1.23.0-alpha.1 release 3c1a3dea59c test images: Adds Windows Server 2022 to the BASEIMAGEs c3509f49f96 Update-vendor to add k8s.io/utils/strings/slices/ 25453708ea2 Remove pkg/utils/slice from kube-proxy b18d6ee61d0 Update cobra to v1.2.1 f5e97186d29 Lower requests b/c multiple containers will leave pending pods ccbdf041a2f Fix slice type comparison bug 0ba731253e0 add tkashem as a reviewer of apiserver 513b55b00d8 hostNetwork tests can't share the same port 6a6e24702c9 Update cri-tools to v1.22.0 fa9d5546cdf Upgrade the default csi-proxy version installed by kube-up.sh f9375f20584 Update kubectl GitHub support issue template 5e03a1f070e Regenerate applyconfigurations ffed59d168c Fix allowed imports for kube-openapi 0e925f266f7 Update unit tests to handle go1.17 certificate parsing error messages 72fd01095de re-order imports for kubeadm b15c2130aad Bump k8s.io/kube-openapi 7cbac6bde0f [volumeScheduling/metrics] Fix buckets initialization 76f03f000a1 Fix use variables in the loop in vsphere_util 04d83edd3c3 SCTP tests run only on 2 nodes 5b3c226c34a Add name and namespace to structuredmerge errors 00dd02f89c8 test images: Use PULL_BASE_SHA for non-git image building cdbfd009dac Mention seccomp annotation removal in v1.25 edc19b80727 fix: skip case sensitivity when checking Azure NSG rules 804ce496e32 image: Change http to https 7953cf0ce9f fix typo of rate limiter 8264dbe17d0 Add unit tests for validateStructuralInvariants 28de406a379 Allocator renames for clarity 907fceb2067 Remove unused NewContiguousAllocationMap 9c4d5b69ecf Fix storage class setup in regional_pd.go a26f7f2b58d Add non-vendor version ldflags 87a4e082aca Change defaulter-gen input to package path a619be8e48f bump gengo to include defaulter-gen package support eba9d33c3ee Fix insufficient privileges to bind to port 37e9517c2f6 Fix typo in CHANGELOG-1.22.md d2a27a58f0a Fix extra latency and add tests for that and width 29bd66d0189 Remove "pkg/controller/volume/scheduling" dependency from "pkg/scheduler/framework/plugins" 4849bdcc0a1 updating co-chairs 27f15035147 rename audit Checker interface aa9380e017a Add termination hook to the startup script - GCE Windows e36a14730bd reducing the number of containers created based on the ports used 6e3923d0a4f send retry-after until ready 096c3e8f2d2 kubeadm: further improve the dynamic version population c295a850c66 update instrumentation reviewers 593eda4ad34 Add unit tests for local volume expansion d68186452d9 apf: free seats in use after additional latency 05beda5c402 Increase time to wait for nodes to become unready 704628fde41 Update golang used in etcd image to 1.16.7 1013e000af5 code cleanup:fix spelling mistake in CHANGELOG-1.22 67e14290aae Fix build with multiple GOFLAGS 145cec925af reduce the number of containers created by 66% 8771d60e541 CHANGELOG: Update directory for v1.21.4 release 874199aff28 CHANGELOG: Update directory for v1.20.10 release c4f18223dab CHANGELOG: Update directory for v1.19.14 release c69f55519e2 Revert "E2E test for kubelet exit-on-lock-contention" 11ed96baf57 generated swagger docs dfaeacb51f9 CSIDriver: allow "StorageCapacity" to be modified ea3c7d98a5c test images: Removes Windows 1903 and 1909 images d9f22688166 test images: Adds sync.exe to Windows agnhost images 94ac8962693 test images: Simplifies the agnhost binary version 3b6cd89f016 add aojea to test OWNERS 1181421112c Update version of Cluster Autoscaler to 1.22.0 e6cb526f6bb set umask on linux and darwin when testing kubeadm copycerts ff7307bf9c2 fix single pointer variable 3af26bae2c3 Refactor defaultpreemption for out-of-tree plugins c799a37654d revert test STABLE declaration 08bec6da0fc Keep MakeMountArgSensitive and add a new signature that receives flags 83889ae5940 apiserver: refactor WithRetryAfter server filter c4ecdad5708 Copy golang license to staging copies 0379c8f96a7 Fix documented version for DisableKubeletCloudCredentialProviders feature gate 3182b69e970 apiserver: add a new mode for graceful termination e8381733068 apiserver: rename test variables f63dbd481fc Warn if docker buildx is not available 95e000fd657 support kubeadm join dry-run 1db36ae3b30 Refactor goroutine counting 75f0a94aba5 Remove 1.20.0 API test data bb08d70f403 Add 1.22 API test data 30e9a420c46 kubelet: fix sandbox creation error suppression when pods are quickly deleted 1ea65e6213c remove listx from OWNERS_ALIASES 86c6e25016a Typo in a comment. b9b76dba6ee Update the unit tests to handle mountFlags 338f8ba0bf8 Add missing interface method in mount_unsupported.go 296b30f1436 Pass additional flags to subpath mount to avoid flakes in certain conditions 3b0c8980824 Regenerate openapi f98ff655647 Drop DefaultGarbageCollectionPolicy checks for legacy apps REST API versions 97c5b8de9ae Drop legacy validation logic for CRD API e3538edc227 kubeadm: update unit tests to support dynamic version updates 207ffa7bdc6 kubeadm: dynamically populate the current/minimum k8s versions 1ceb118e3cb Drop legacy status logic for volumeattachments API c702dd43940 Drop legacy validation logic for networking API b1d344db44d Drop legacy validation logic for certificates API befffd1565e Drop legacy validation logic for admission registration 8fd371353c1 Fixes 104067; Explicitly states Docker CLI plugin buildx required for building using Docker 39a1293cbc8 Drop beta REST APIs removed in 1.22 808659cc428 pin-dependencies.sh: support switching repos 768d69a423a add 'projects/' suffix if this library is used with an older version of the google api library cdc225f2979 bandwith --> bandwidth 2c2661a4113 e2e test: lock-file and exit-on-lock-contention 5eae896d71a Remove AllowInsecureBackendProxy feature gate 4af506c9895 Add getOSInfo err info 73a5cce3e64 device manager: do not clean admitted pods from the state 93a237abd82 memory manager: do not clean admitted pods from the state 66babd1a90c cpu manager: do not clean admitted pods from the state 85d83ebd288 staging/publishing: Set go1.15 version to go1.15.15 619e38141b6 remove unnecessary waits from watch conformance test 1ce594b7ee0 Fixes flaky GKE kubectl test 80ca6a4ae6f Some cleanup of the package for event clocks dc079acc2be sched: retry unschedule pods immediately after a waiting pod's deletion 4f1b1d72e31 Update setcap image to buster-v2.0.4 cafad985366 Update debian-iptables image to buster-v1.6.6 08d8f29a7a3 Update debian-base image to buster-v1.9.0 d166cabd9e2 Add e2e for local volume expansion f9efd14d443 TAG used when building pause is configurable b98594bc793 Add ibabou to gce/windows OWNERS file d2ed3b28b79 Revert "revert Bump DynamicKubeConfig metric deprecation to 1.23 by delta update" 6b9dc099f88 [go1.16] Update to go1.16.7 296c18ec323 apf: estimate list width 7db782ee039 apimachinery: remove unused ignoredConversions map and nameFunc in converter. b66d52f6a8b make notes more easily to understand 561ce035b5b Avoid spurious calls to update/delete validation 00d89aad506 Allow a custom kube-cross image + tag to be specified c2a3b793d3e apf: use EventClock rather than a PassiveClock for queueset 023f6a90db8 Add SergeyKanzhelev to node e2e test approvers ddaa06abeea Propose myself as a reviewer for cluster/gce/gci c8431f42d9a kubeadm: Reduce the backoff time of AddMember for etcd dfde50b1856 fix unsafe json construction for digestConfigObjects. 8ed1628a6e7 Add a new webhook metric tracking request totals. 3cfe3d048ff Improve dynamic cert file change detection f9a791ff262 Remove kubectl book a947c32783e Add feature gate to disable in-tree credential providers d866272d65a Correct comment related to HugePageStorageMediumSize feature gate a04a98154e5 Remove the StartupProbe feature gate af2129b77d0 Allow override of `CGO_ENABLED=0` d9d41b70f64 Fix metrics reporting for the deprecated watch path dcb298c9552 Introduce event clocks based on k8s.io/utils/clock 2c60feffbee apiserver: add callback to get notified of object count c486b229d28 refactor(kubeadm): remove the flag --port from KCM manifest 9351b57defe Skip node e2e test for recovering from ip leak with docker ff0e1f4fe97 Add the pod field to all volumeToMount info level logs 691b45e220c Clarify ready (#103782) 9cf3ad5cffa Remove duplicate dependencies from 1.22 changelog 952aa1b2d26 add integration test for apiserver hsts ff165c88239 Replace usage of Whitelist with Allowlist within Kubelet's sysctl package (#102298) 3e44139ae46 [jobs][registry]: Warn if no propagationpolicy set 9cffbab037e Log kube-env variables from startup script a7834389b44 check APIStatus.Code in Is* family of functions 5d84ffa6c26 Update configure-helper.sh b0039559ddf Update configure-helper.sh 572a24d854e add a keepalive time to the konnectivity server 0376c58c44d Update configure-helper.sh ab595f37d25 CHANGELOG: Update directory for v1.22.0 release 8cf10d9a200 set showHiddenMetricsForVersion=1.22 in dynamicKubeletConfiguration test 9d30eb88dfd retry apiserver errors on e2e service tests ea1bc18bc17 Use docker buildx for etcd image ee7562a2f8a add clusterIP allocator metrics 94a58a3b146 remove GAed feature gates sysctls ac076838c81 Add ehashman to node e2e test approvers 3463c2dfa97 Skip NVidia GPU test in node e2e CI jobs for containerd and other runtimes 4efc9a95695 Fix zone calculation - consider only untainted nodes c8208247113 Add pod context to volume lifecycle logs c35502ad4bd Remove AUFSUmountHung from NPD test dab19517e5a Explicitly restart kubelet to stabilize serial-containerd job 980cf854397 revert Bump DynamicKubeConfig metric deprecation to 1.23 by delta update 72223406ac6 Remove stray DNS port references in NetPol tests b7ea7a7766b kubeadm: disallow the mixture of --config and --patches 375ef778c4b kubeadm: remove deprecated --experimental-patches 34f49596332 replace e2e WaitForPodsReady by WaitTimeoutForPodReadyInNamespace 7e2d6301bf9 [k8s.io/kubectl/pkg/drain/drain]: minor typo fixup 1a3eda9394b fix: 81134: display conflicted taint without a json representation. a77f4f4c29b Log e2e-node kubelet output directly to file 163e4974b63 e2e node server: fix crash in log line 1a87ae19a62 Revert "Add a namespace label to admission metrics and expand histogram range to 0-10s" 09dc055984e Update golang.org/x/time/rate (#104014) a2a22903bc0 delete stale UDP conntrack entries for loadbalancer IPs 2635415482b fix error variable name 9f735e71bbb Simplify APF promise to what is really used in the code 9cee586ee98 apiserver: avoid repeated loading context for requestInfo in Namer.Name c406f2edab6 Fix: ignore not a VMSS error for VMAS nodes in reconcileBackendPools f720c4fd44b hack/verify fixes ecb38137269 Update component-base OWNERS to include SIG-Architecture fec260d083f Add release note block to cherry-pick script 260b5ef1554 fixing scripts from https://github.com/google/protobuf/releases to https://github.com/protocolbuffers/protobuf/releases 59a7cc12c9f Mark failing node serial tests as flaky b5f24c334e4 Bump DynamicKubeConfig metric deprecation to 1.23 a1cf44eab44 Remove unused promise code from APF 05cfbecab99 test images: Adds image labels by default bbb368b7012 Update e2e test images url 4549573a447 minor cleanups ca90849724e add kube-openapi/pkg/schemaconv to kubeadm import-restrictions 4606ebe423a update node-problem-detector v0.8.9 99bc2b077fd Added support for multiple --from-env flags 4edb6e01bed Add kube-openapi to client-go import restrictions df1d9380fbd Fixes (temporarily) curl piped to shell security vulnerability 3628065b455 fix boilerplate and staticcheck 85bc3c4f857 fix vendor 49c86bde556 fix extract_test af11c4ac9be remove apiserver impor from client-go 93ef5acb35f Fix kubectl version unit test a4dfe406507 Start the informerFactory in the ControllerContext db48793269e Set idle and readheader timeouts f1e1f3a416b Fix disruptive subPath test failures 363d47c08c8 staging/publishing: fix rules for legacy-cloud-providers for 1.22 d38c2df2c4b client-go: deltaFIFO trace slow handlers 55765f1b49e sched: support HistogramVec in scheduler performance test 479e2ae307c wrap extractor errors 7bfc420351f simplify test to only test the new logic of extractUnstructured 1122091b065 Revert caching in favor of simple ttl 53582a0104f remove commented out code c9e97de46bb Address PR feedback around gvk parser generation ergonomics 9b9925f56db Restructure caching logic 7cb18e84f13 comments f6ce385e444 remove test script 604db6eb2ad rename cache, add to integration test 235a57a29e5 Add HasOpenAPISchemaChanged to DiscoveryInterface 7b9757faa49 basic caching working dda31bbf2e7 Manually set GVK in extract, add commentary to extractor 9f4a4d812d2 Write TestUnstructuredExtract 6e481c5db19 Initial UnstructuredExtract without caching b15ed04c9dc Allow non-subsetting ILBs to update when the feature is enabled. 2ad2bc68443 kubectl: Add labels to ingress describe 004e4414839 refactored master to controlplane 00080d400fe Allow customizing spam filtering in event client library 822eb29b6f3 client-go/events: avoid referencing a nil related object 1555877cc5d fix data race for Test_Run_Positive_VolumeMountControllerAttachEnabledRace 8dc091ef2e2 Fix wrong log ae7b9787ee7 cleanup description on deprecated include-uninitialized flag dc9eb82e0aa Fix NPE in test/e2e/framework/providers/azure 7fa0b9b6c10 add --concurrent-ephemeralvolume-syncs flag for kube-controller-manager 93146048b4c Mark "update Node.Spec.ConfigSource" node e2es as slow 4115bef8268 Update references to test/conformance/image 024930df119 Move cluster/images/conformance to test/conformance/image 3520e8b3393 Fix a typo in comment 75f0007d2bc Overlaid OS's environment variables with the ones specified in the CredentialProviderConfig 00e31ce565a Fix incorrect comments in scheduler_queue.go fef5c0c1a63 Improve storage test skipping pattern. 523b4c0918f Replace 'x.Sub(time.Now())' with 'time.Until(x)' 326471d8806 k8s.io/code-generator: Change BoilerplatePath() to locate file or require explicit flag 2cacfada265 Update Containerd version - GCE Windows 45cf1697ba0 Changed flag name underscore warning to avoid recommending potentially invalid flag name 97ba475941f add new metric 94977dce8d1 Update doc description for --audit-log-maxbackup 971e0c4400c Fix a typo in comment f174307e494 k8s.io/code-generator: Enable generate-* scripts usage as module deps 8ad83fd685f Make crictl tests host local 80e4007bc3b test: e2e: HPA ContainerResource 5be47eaf275 kubeadm: update references to legacy artifacts locations e2b6816953c Deprecate apiserver_longrunning_guage and apiserver_registered_watchers 019e8f71b6a refactor: normalizing URL string locally and move out from purell package 38239d3025d migrate cmd/kube-proxy/app logs to structured logging dd2c3830600 decouple timeBudget from real clock 66803689585 Add: specify that reason is a field to record the reason why failed 6490fcc5bbc setting the status to fix on the known issue 9f09064104e feat: Provide IPv6 support for internal load balancer 51e4694cd66 fix typo scheduling queue to active queue ef181c14e12 Provide reference to impersonation options for kubectl auth can-i command. b09bbd808ae testing patches. add k8s.io/staging, remove local home 6d988acb558 Ignore 'wait: no child processes' error when calling mount/umount d05b232afc8 optimize the code 5fdfe872d61 e2e: update makefile example for building images ac09f7a8bd3 TODO comment should have been removed with #2912, the restartCount docs wasn't updated as part of #6794. 318b9a95786 remove superfluous [Feature:SCTP] tag in some test names 50b3cbe9990 e2e: remove unused sync.WaitGroup 9d405710fe7 e2e: remove runKubernetesServiceTestContainer 5347f67e35b Using full url format as runtime endpoint d9b8c5f992c add deprecation for Azure Disk Kind in csi migration baf0bf831d1 Fix typo in comment in endpoints_controller f0b34bd24a7 Pass unknown labels in allowedTopologies during CSI translation 4101c8b3cb3 Set out.TargetCPUUtilizationPercentage correctly when converting autoscaling_HorizontalPodAutoscalerSpec to v1_HorizontalPodAutoscalerSpec 1980b18c458 Solved the test problem and added update comment d1e9da9f8a0 update comment with EnqueueExtensions 5f0925a2941 Flake #99979 increase delay for ready state propagation 1887ddfc968 Make --configure-cloud-routes configurable in local-up-cluster 169583bf4ed tests for path resolver, add KUBE_ROOT to both top level func calls 2d3323d1fb4 try to fix the in_tree_volumes cases: refactor the projectBasePath logic 82728b5f71d Add integration tests for updating Job parallelism 7911a08fb31 Remove ServiceAccountIssuerDiscovery feature gate e75f3fb563e add happy path tests for two types of imports d3aabe23974 fix existing unit tests 585ce7f04dd missed a paren bde2ef2a1a0 review comments 60d446fe3db Drop end of sunrpc port range to avoid port conflicts. c79a0a08828 Get rid of unused flowSchemaRVs in P&F 73211256e8f Rename width to workEstimate in P&F code 2b03c771895 e2e: fix NFS options test for IPv6 d02568aab52 client-go/tools: update events version in doc 7a36a5b827e fix test failures in legacy cloud provider: add 'projects/' after upgrade ef3c344868d seems to work, needs tests and a lot of cleanup 2bc5ff6ab34 Set EC2 instance cache max age to 10 mins 2926b4572e6 upgrade google.golang.org/api to v0.45.0 18d583653c6 upgrade github.com/prometheus/common to v0.28.0 abd8acc2599 fix exec failure for gomock finish calling 6c87c222771 Add structured logging for more steps a9b7dcc8c21 kubelet: update remote runtimes for cri stat changes 2dc2b1e239d CRI: add fields for pod level stats to satisfy the /stats/summary API a9a3c4bb9aa Refactor of TestValidateIngressClass and TestValidateIngressClassUpdate methods by adding Boilerplate in helper functions #FIXES: 99005 bf9f3dc7b3d deprecate unused option deployment-controller-sync-period for deployment controller 927d0c39322 cleanup: Removes GcrRelease and SampleRegistry from manifest.go abf735daa83 remove stack trace log when sorting with a bad unsortable field 18955db4161 fix azure disk translation issue 5d80d6e7c3d Make cpu request of kube proxy configurable by env variable. de442ef8604 Retry hostname->IP: [Errno -2] Name or service not known 03f9f75e880 fix typo for daemon_controller_test.go f2eec0a8167 ResourceConfigForPod: check initContainers as other QoS func a7c48e97076 images: Removes OS Version workaround for manifest list images 97bcfbd674b Allow the actual inhibit delay to be greater than the expected inhibit delay d9be5abc378 kubelet: add shutdown events 0839c00b76b Increase pressure timout on DiskPressure test 992993257d8 Removed usage of github.com/pkg/errors 8eee78a61f0 Update github.com/pkg/errors to go native errors pkg 7b98a0770fe remove not used IsStaticPod, prevent possible panic f9e4a015e22 tests: Spawn poststart / prestop pods on the same node as the http pod e2477171ca2 Ensure images are pulled after eviction tests a93ad421ee9 Return StatusError 404 in fake client when resource is not found a0e8a98bcb6 Add support for expanding local volumes c882437f220 e2e test: bump ProgressDeadlineSeconds in Deployment iterative rollouts 9d636fea046 e2e test: fix Pause in Deployment iterative rollouts a1e56b4f6d1 Update the typo in values of pods in performance-config.yaml 5b426818404 Correctly drain timer 6a0452e861e cleanup: fix errors ending with punctuation in proxy 82402c5af0c Omit redundant nil check in type assertion 68ec18a050d code-generator/register-gen: groupName can't use '// +groupName=somegroup ' to override 1dc4a29a1ae fix typo in retry doc 7aab5df381f use already defined variable 72271dcc9c5 Fix error path in file /verify-prerelease-lifecycle-tags.sh. 82a9fb9d0ec subatomic: Creates the symlinks to user-visible files later Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* uxen: update guest tools to 4.1.8Bruce Ashfield2021-08-271-4/+4
| | | | Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* kernel: add 5.13 pattern, remove 5.4Bruce Ashfield2021-08-191-0/+0
| | | | | | | oe-core is moving to a 5.10/5.13 reference, so we adjust our matching versions. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* image-oci: use new override syntaxBruce Ashfield2021-08-061-1/+1
| | | | | | | The dependencies of the image-oci class were missed in initial conversions. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* image-spec: explictly reference main branchBruce Ashfield2021-08-021-1/+1
| | | | | | | The oci-image-spec repository has dropped its master branch, so the fetcher default no longer works. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* conf: set compatibility to honisterBruce Ashfield2021-08-021-1/+1
| | | | | | | With the overrides conversion changes, we mark master compatible with honistor only. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-distribution: manually finish override syntax conversionMartin Jansa2021-08-021-1/+1
| | | | | Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* global: overrides conversion pass 2Bruce Ashfield2021-08-025-10/+10
| | | | Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* global: overrides syntax conversionBruce Ashfield2021-08-02122-595/+596
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | OEcore/bitbake are moving to use the clearer ":" as an overrides separator. This is pass one of updating the meta-virt recipes to use that syntax. This has only been minimally build/runtime tested, more changes will be required for missed overrides, or incorrect conversions Note: A recent bitbake is required: commit 75fad23fc06c008a03414a1fc288a8614c6af9ca Author: Richard Purdie <richard.purdie@linuxfoundation.org> Date: Sun Jul 18 12:59:15 2021 +0100 bitbake: data_smart/parse: Allow ':' characters in variable/function names It is becomming increasingly clear we need to find a way to show what is/is not an override in our syntax. We need to do this in a way which is clear to users, readable and in a way we can transition to. The most effective way I've found to this is to use the ":" charater to directly replace "_" where an override is being specified. This includes "append", "prepend" and "remove" which are effectively special override directives. This patch simply adds the character to the parser so bitbake accepts the value but maps it back to "_" internally so there is no behaviour change. This change is simple enough it could potentially be backported to older version of bitbake meaning layers using the new syntax/markup could work with older releases. Even if other no other changes are accepted at this time and we don't backport, it does set us on a path where at some point in future we could require a more explict syntax. I've tested this patch by converting oe-core/meta-yocto to the new syntax for overrides (9000+ changes) and then seeing that builds continue to work with this patch. (Bitbake rev: 0dbbb4547cb2570d2ce607e9a53459df3c0ac284) Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* xen-image-minimal: fix aarch64 build for non-qemuboot-enabled machinesChristopher Clark2021-08-021-1/+1
| | | | | | | | | | The qemuboot device tree generation task in qemuboot-xen-dtb.bbclass requires the QB_SYSTEM_NAME variable to be set to identify the Qemu binary to use. Skip the task if it is not set. Reported-and-tested-by: Jon Mason <jdmason@kudzu.us> Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* k8s: update kernel configuration featuresZqiang2021-07-291-1/+17
| | | | | | | | Add kernel config fragment according to the requirement from the file types_unix.go in source codes of kubernetes. Signed-off-by: Zqiang <qiang.zhang@windriver.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* python3: remove the no-longer required bbappendRuslan Babayev2021-07-292-9/+0
| | | | | | | | | It has been carried over from python2 and is no longer required. More importantly it breaks the python3-native build due to ${STAGING_DIR_TARGET} being "" for native recipes. Signed-off-by: Ruslan Babayev <fib@cisco.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* qemuboot, xen-image-minimal: enable runqemu for qemuarm64 Xen imagesChristopher Clark2021-07-294-2/+245
| | | | | | | | | | | | | | | | | | | The Xen hypervisor built for Arm 64-bit targets can be launched with runqemu by providing a Device Tree binary and configuration for Qemu, which enables interactive testing of Xen images. Add qemuboot-xen-dtb.bbclass to add a new bitbake task for generating the dtb file by using lopper on a device tree produced by Qemu. Add qemuboot-xen-defaults.bbclass to supply working default parameters for the qemuarm64 machine and general support for qemuboot for Xen, and adjust the defaults as needed to boot successfully in testing. Development aided by this script by Stewart Hildebrand of DornerWorks: https://gist.github.com/stewdk/110f43e0cc1d905fc6ed4c7e10d8d35e Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* lopper, python-dtc: add new recipes for device tree toolsChristopher Clark2021-07-292-0/+73
| | | | | | | | | | | | | | | This device tree tooling is being added as a prequisite for enabling qemuboot with the Arm 64-bit version of the Xen hypervisor. lopper: a tool for performing operations on device tree files. A new recipe inspired by the original from meta-xilinx-bsp. python-dtc: a python library for the Device Tree compiler. This is a prerequisite for lopper. Updated import of recipe from meta-xilinx-bsp for the latest release, version 1.6.1. Signed-off-by: Christopher Clark <christopher.clark@starlab.io> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* k8s: update to v1.12.0-alphaBruce Ashfield2021-07-271-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping kubernetes to version v1.23.0-alpha.0-33-gd9d4f0c69cb, which comprises the following commits: 363d47c08c8 staging/publishing: fix rules for legacy-cloud-providers for 1.22 6d1556df7bb Update to using apiserver-network-proxy v1.22 7728428f017 Do not try to create an audit log file named "-" 77afa53f9d3 Add e2e testing manifest bundle to e2e_node test suite 0cce9a4a6c6 Remove conformance status from a sysctl test and relabel 0aa16fae5b8 staging/publishing: add release-1.22 rules 3af4fe8c9b6 Use pointer gomega comparison for UsageNanoCores 2a4a1c1d005 disable aufs module 0610968bfaa bump metrics-server to 0.5.0 c5aead020b6 cluster: fix CI metrics-server deployment 9103b7187c9 Fetch metrics from controller manager & scheduler no run once 236e72cf8a9 Make CSR cleaner tolerate objects with invalid status.certificate c1bac408803 Fix SIG Node SSH e2e test 33feaee2c2d Fix windows storage tests fac3dd6914f CHANGELOG: Update directory for v1.22.0-rc.0 release 59c0523bca0 Using ServiceIPs instead of DNS names in the NetworkPolicy Probes + adding Interface decoupling (#102354) 536cf819747 Add konnectivity agent to log dump d7ee024cc5d kubelet: Make condition processing in one spot c2a6d07b8f0 kubelet: Avoid allocating multiple times during status 9efd40d72ad kubelet: Preserve reason/message when phase changes 9d0b32858a5 update cos 85 version to latest. e5b434e990d kubelet/cm: don't set Devices eb5df869baa vendor: bump runc to 1.0.1 aeb82243fc8 Revert "tests for statefulset PersistentVolumeClaimDeletePolicy api change" faed88bb720 Add additional APF test for handling other panic types ef435b85b47 Optimize APF support for watch initialization to fix the pod startup time regression. 1f2902a336c Fix panic in master upgrade tests e5a1f86e0ac add apiserver tracing integration test, and fix endpoint validation 10a3cc815be Revert "statefulset PersistentVolumeClaimDeletePolicy api change" fb5b966a88a Revert "Add StatefulSetAutoDeletePVC feature gate" 0d1aa3a1b87 CHANGELOG: Update directory for v1.21.3 release 1e5ba82fd0b CHANGELOG: Update directory for v1.20.9 release fc6a5be694a CHANGELOG: Update directory for v1.19.13 release be34dc95b5d Remove E2E test for NodePreferAvoidPods scheduling Score a2ea04bab3e tests: Updates cuda-vector-add:1.0 image to the promoted registry a3b6f0557d2 device-plugins: replace gcr.io/gke-release to use the community registry f5bc129a991 CHANGELOG: Update directory for v1.22.0-beta.2 release a6ac42082b4 client-go exec: fix metrics related to plugin not found 5e1b5ec398c Revert counting deleted pods as failures for Job 75748c185ea enable verify-golangci-lint.sh 07332ad3985 fix ineffassign and varcheck 26cc8e40a8f fix deadcode issues b74fe232e34 update golangci-lint to newer version 416efdab26a Remove Endpoints write access from aggregated edit role 6c61ee51b90 Revert granting EndpointSlice write access to edit role de9cdab5ae3 kubelet: Prevent runtime-only pods from going into terminated phase aaa7de0ac67 Update API description for probe.terminationGracePeriodSeconds bf2ae14501e Move feature flag to beta (but leave as false) and remove the feature flag from Kubelet 83f8d1ad72d [go1.16] Update to go1.16.6 65618bfd696 Add sync reconstructed volume from desired state of world for volumemanager 9fa641b9add test/integration/endpoints: check for pod existencen in TestEndpointWithTerminatingPod 1280a365e4a Revert "use PermitWithoutStream=true for etcd: send pings even without active stream" bc475373b24 Drop direct dependency on gotest.tools 32783f75684 PodSecurity: Initial webhook implementation 2878e472ad7 test/integration/endpoints: improve docs for TestEndpointWithTerminatingPod 0aa1b3b0bfc test/integration/endpoints: add a test to ensure Endpoints does not include terminating pods 642eff0c69d Rename NodeSwapEnabled flag to NodeSwap d1ef44242a3 Make khenidak a sig-net approver c2aaf0667fd PodSecurity: make integration tests run sparsely 9dd59017c4c add tracing to webhook requests 581b088f760 integration test: provide a timeout for /health a570008cbd6 apf: fix virtual clock 5918869ed6c Revert 103327: "kube-scheduler: ensure the default config output of --write-to-config is usable" 1727cea64c1 Fix index out of range if multiple default plugins are overridden b14c10ae301 create LeaderMigrationConfiguration v1beta1 40b2155ddb7 promote ControllerManagerLeaderMigration to beta. 995278c9fbb add ControllerManagerLeaderMigration as beta 513bd93f76d update test for feature gate 412962204ff Fix the code is leaking the defaulting between unrelated pod instances 2b88dc381e1 [PodSecurity] Add test coverage for pod-template-containing objects 0fa01c371c9 Mark volume mount as uncertain in case of volume expansion fails fd0db61d6c3 test/intergration/endpointslice: add tests for endpointslice terminating condition 826a5219dac promote EndpointSliceTerminatingCondition to Beta a2fb8b00392 smtalign: e2e: add tests 23abdab2b77 smtalign: propagate policy options to policies 6dcec345dfb smtalign: cm: factor out admission response c5cb263dcf2 smtalign: propagate policy options to cpumanager 6dccad45b4f smtalign: add auto generated code cc76a756e40 smtalign: add cpu-manager-policy-options flag in Kubelet 649b87aaf85 prevent mutation of deletion options during delete collection d95b14e1abf Revert "apiserver: add callback to get notified of object count" d5d9327351d Only use dualstack if the node and config supports it 8e2b728c68a Explicitly skip host file mounting for windows 2dd26221881 Track Job Pods completion in status 7da1a0b2304 update the help text of KubeletConfig following the DynamicKubletConfig feature deprecation 41c5bca3496 kubectl: update set command description to include cronjob resource (#102503) bb56a0bd048 Add Job.status.uncountedPodUIDs 418fa71b6b1 Simplify use of the fake dynamic client 62d7a417fa6 CHANGELOG: Update directory for v1.22.0-beta.1 release 40f1db8d2d4 update license gathering script for forked code 79e230ea212 fix kubelet panic when DynamicKubeletConfig enabled b6b3a692843 Don't set sysctl net.ipv4.vs.conn_reuse_mode for kernels >=5.9 369c4a2b98b Use cmp.Diff() replace reflect and diagnosis 7f9d2eda828 limit warnings to requests that would otherwise succeed, reformat warning message 36907db929e PodSecurity: Drop field path from container visitor 78953990777 PodSecurity: seLinuxOptions: regenerate files d5419707516 PodSecurity: seLinuxOptions: cleanup 19c8ab297c0 PodSecurity: sysctls: cleanup e178695c25b PodSecurity: seccompProfile_baseline: regenerate files bebf6129672 PodSecurity: seccompProfile_baseline: cleanup 2af08d1a5a0 PodSecurity: seccompProfile_restricted: regenerate files 88a12412998 PodSecurity: seccompProfile_restricted: cleanup 43146d4377f PodSecurity: runAsNonRoot: regenerate files 5fc06591a2c PodSecurity: runAsNonRoot: cleanup edb7cdb02aa PodSecurity: restrictedVolumes: regenerate files 676240a342a PodSecurity: restrictedVolumes: cleanup 4a69c579923 PodSecurity: procMount: cleanup f9b8dfd0e69 PodSecurity: privileged: cleanup 7c704674003 PodSecurity: windowsHostProcess: regenerate files 9dce1d6a493 PodSecurity: windowsHostProcess: cleanup 45485bb7aea PodSecurity: hostPorts: cleanup f709cf05f41 PodSecurity: hostPathVolumes: regenerate files a39c448684a PodSecurity: hostPathVolumes: cleanup 826c57701c7 PodSecurity: hostNamespaces: cleanup 62b71175e74 PodSecurity: restricted capabilities: regenerate files f10dfc6e304 PodSecurity: restricted capabilities: cleanup bd4dc42a72e PodSecurity: baseline capabilities: regenerate files 809abf4f5b9 PodSecurity: baseline capabilities: cleanup b390e9e32dd PodSecurity: appArmorProfile: cleanup 8291f8490b9 PodSecurity: allowPrivilegeEscalation: regenerate files 1e2886341a6 PodSecurity: allowPrivilegeEscalation: cleanup 648b970718e PodSecurity: add message helper 92541f46e6b Restore ability to print long strings 5d80665b0a6 Fix dbus config path for GracefulNodeShutdown e2e 6c72fbaa899 update vendor after switch 79d0c6cdc10 switch from golang-lru to the one in k8s.io/utils 3a221b33324 update to new k8s.io/utils a3f57886a26 fix CleanScope so we can resolve correct verb for apiserver_request_terminations_total a6b30e96294 podsecurity: added ValidatePodSecurityConfiguration c3d9b10ca83 feature: support Memory QoS for cgroups v2 80dda49ce22 Service: Fix semantics for Update wrt allocations 6cf3e36c370 kubeadm: statically default the "from cluster" InitConfiguration 0a42f7b9890 Graduate EndpointSliceProxying and WindowsEndpointSliceProxying Gates 1dfacd3c702 PodSecurity: use code/reason/details from admission library fb9cafc99be sched: provide an option for plugin developers to move pods to activeQ 9bd857ca047 Truncate endpoints over a 1000 addresses d9e3fbff949 apf: fix bootstrap ensurer log message bb3fe633b47 add test for triggering race condition 33e6ebc8f8d update translations ab1807f2bcb copy podStatus.ContainerStatuses before sorting it 1e0f695afa9 fix translations location in update-translations.sh 6408f3dffc0 Update generated files 250f47a45c5 Rename to capabilities_restricted 08608a24f14 Update dropCapabilities check/fixtures ce257266aa7 client-go: copying object to fix data race (#103148) 2c116055f7e [disruptioncontroller] Don't error for unmanaged pods a8793dcb3e2 Implement check_dropAllCapabilities.go and test/fixtures_dropAllCapabilities.go 3fadea4ea2e Bump version of Addon Resizer used by Metrics Server 6b736f34848 Minor adjustments to descriptions and example text cea1dcfeed2 Add watch tracker to APF for request cost estimation 2df05df6982 Avoid code duplication in watchcache 96406b915d3 Clean up the remaining master names in test/integration 7f1c4977d7a Refinements to pick queue logic in P&F 26e83ac4d43 kubelet: ignore /dev/kmsg error when running in userns 192790c52fe kube-proxy: allow running in userns dbe01551397 kubelet/cm: ignore sysctl error when running in userns b16323e37ce New feature gate: KubeletInUserNamespace af19d7f415d fix delete nil pointer panic d8fe255f413 Add test for validateProbe e378600c90d Add validation for Prober TerminationGracePeriodSeconds 1ff5ae2cb5f Regenerate 20de04d6c30 Update API documents 00dba76918e Add DataSourceRef field to PVC spec 5b787aa1843 Clean up testing of AllocateLoadBalancerNodePorts eae4a19bd35 Fix small bug with AllocateLoadBalancerNodePorts 3eadd1a9ead Keep pod worker running until pod is truly complete 68dadd40d63 Fix pkg/api/pod/util tests to ensure feature gate is set adcfcfa2e78 add yaml separator validation and avoid silent ignoration 04d59ff2df3 test/e2e/network: add Service internalTrafficPolicy test for pod (w/ host network) -> pod (w/ host network) 9977ea371b1 test/e2e/network: add Service internalTrafficPolicy test for pod -> pod (w/ host network) 025c95a778b test/e2e/network: add Service internalTrafficPolicy test pod (w/ host network) -> pod f6bc5d01402 test/e2e/network: add Service internalTrafficPolicy test pod to pod 2d0f99fba18 Fix resource metrics e2e test 28152a26fee fix: return empty VMAS name if using standalone VM ad8275f294f Added unit tests for ExpandPathsToFileVisitors dffc2a60a28 deprecate and disable by default DynamicKubeletConfig feature flag 68ccb8a9477 Use system-validators v1.5.0 b1f34ea205f add RetryOnConflict to pod status updates 6d4096cc69a Upgrade kustomize-in-kubectl to v4.2.0 a46b42a92b8 Manually update kustomize attachment points. 212ce7c2871 Shorten test time a42c066af70 Fix Data Race in nodeshutdown restart c69ad8c57a3 e2e: increase readiness gate timeout 71f810bb71e Add distributed tracing to the etcd client babebf76d39 Apply PSP container tests to EphemeralContainers aff49ca6846 Generated code for securityContext in EphemeralContainers 70765fa24d5 Allow securityContext in EphemeralContainers ebe550bd488 Upgrade etcd to 3.5.0 7839668877e GCE Windows: Set TCP/IP parameters to keep idle connections alive on GCE. 30d2ad576ac Remove ManagedPod,ManagedContainer metrics 1c8675fc02f Ensure node e2e apiserver and test suite can open enough files c4e644406ed test images: Adds windows-nanoserver image d5cb5065c46 Skip node container manager test on systemd 03d60a89a0c Add build instruction for buildx CLI plugin 82e4ab5ec62 Improve slice allocation in LabelSelectorAsSelector 19c23949154 Add benchmark for LabelSelectorAsSelector 3f0b64ec959 kubectl: show consistent unit format in quota describe 0a83041d4d3 remove Factory that not used 9e372bffeff e2e: test SSH port on NodeSSHHosts c12aa0f6b75 promote HugePageStorageMediumSize to GA 849dbe034b3 use PermitWithoutStream=true for etcd: send pings even without active streams 29178fff1c9 Add kubelet managed pod metrics b42c1a3e474 test images: Adds cuda-vector-add-old image a70323d6320 Updating OWNERS_ALIASES for SIG-Windows Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update to 3.2.3 latestBruce Ashfield2021-07-271-1/+1
| | | | | | | There's not much here, but we pickup the 3.2.4-dev parsing bump in preparation for that development stream. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* containerd: update to 1.5.4Bruce Ashfield2021-07-271-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | Bumping containerd to version v1.5.4-12-g1c13c54ca, which comprises the following commits: 7b17268fd remotes/docker/pusher.go: Fix missing Close() 2f11d5855 remotes/docker/fetcher.go: Fix missing Close() 4c1722e2b Update docker resolver to authorize redirects 166a81f88 snapshot/devmapper: log exported methods correctly d2cb9949b go.mod: runc v1.0.1 6807d070e update runc binary to v1.0.1 81cfab8f5 Prepare release notes for v1.5.4 d9b284bfd Try next mirror in case of non-404 errors, too 48d7a5c5c Prepare release notes for 1.5.3 defaec610 Update mailmap 43d089233 integration/client: go mod tidy ac7bd5483 Update Go to 1.16.6 (cont.) 385d9ed00 Update Go to 1.16.6 a695a0704 [Vendor] Update hcsshim to 0.8.18 0515f9d2d Fix missing Body.Close() calls on push to docker remote f5c7cb6e0 Add test for archive breakout test for lchmod 37a44de17 Cleanup lchmod logic in archive 78b95dff2 update runc binary to v1.0.0 GA Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* k3s: update to v1.21.3Bruce Ashfield2021-07-261-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping k3s to version v1.21.3+k3s1, which comprises the following commits: 786f91b997 Fix multiple bootstrap keys found b9cc6409f4 Bump containerd to v1.4.8-k3s1 c15259d925 Fix to allow prune to correctly cleanup custom named snapshots (#3649) (#3672) 659002f153 [release-1.21] Upgrade k3s-root version 9c981b0184 [release-1.21] Bump Kubernetes to v1.21.3 (#3652) 9859ec7a81 [release-1.21] - Backport Fix storing bootstrap data with empty token string (#3514) 5a88b5b3ea Emit events for AddOn lifecycle ab0520f44e Add comments, clean up imports and function names 411d7e6753 Tidy up function calls with many args ff0451c4dd Add nodename to UA string for deploy controller c3d134a405 prevent snapshot save when snapshots are disabled (#3475) (#3610) 267adf64dc Bump the packaged runc binary version 42ab13a869 Update etcd snapshot error message to be more informative when etcd database is not found (#3592) bbd4fb9888 Dispatch to rancher/system-agent-installer-k3s when tagged 0c5577a8ec [Backport 1.21] Update embedded kube-router (#3557) (#3595) 04d425289f Fix spelling to satisfy codespell check 733ca42b6a go mod vendor 9863b92eb4 Bump rancher/klipper-helm image in airgap image-list.txt 0a5bca7ea2 Bump helm-controller to v0.10.1 0c2d8376d0 Changes local storage pods to have 700 permissions (#3537) (#3548) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-ce: update to 20.10.7Bruce Ashfield2021-07-261-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping docker to version v20.10.7-41-g013d6655bb, which comprises the following commits: 067918a8c3 [20.10] update containerd binary v1.4.8 b0da207af4 Bump go 1.16.6 (addresses CVE-2021-34558) abe8c4e80d updated vendored archive/tar to go1.16.5 7c6645b32b update archive/tar patch for go 1.16 55c363ef48 Bump go 1.16.5 8b0913935c integration: ensurePlugin: disable go modules when building plugin 09a7efb1f7 hack/ci/windows.ps1: disable go modules 6793ff26d8 pkg/fileutils: TestMatches: remove cases no longer valid for go1.16 ab9a92f79c Update test certificates 1d4a06e610 hack: add script to regenerate certificates feaca9816a hack/vendor: add check for vendored archive/tar 793340a33a [20.10] update containerd binary to v1.4.7 7429792eed docker pull: warn when pulled single-arch image does not match --platform 72b66d56a5 [20.10] vendor github.com/Microsoft/hcsshim 64a2b71405dacf76c95600f4c756a991ad09cf7c (moby branch) 50c392c9ff API: fix 404 status description on container create 025e3a7898 Update v1.41.yaml b9cf7b7db5 rootless: fix "x509: certificate signed by unknown authority" on openSUSE Tumbleweed 869b50e10b rootless: disable overlay2 if running with SELinux 44f95c7126 dockerd-rootless.sh: avoid /run/xtables.lock EACCES on SELinux hosts 78bb0f445a Dockerfile: update go-swagger to fix validation on Go1.16 618f6a79ab Run s390x tests on Ubuntu 20.04 872cb16edb update runc binary to v1.0.0 GA 4d42e18c05 vendor: swarmkit to fix deadlock in log broker 89edb68e89 Fix possible overlapping IPs 523f8b397c Jenkinsfile: skip ppc64le and s390x by default on pull requests a57fc0eb15 Fix setting swaplimit=true without checking 6474dada20 vendor: github.com/moby/buildkit v0.8.3-3-g244e8cde 895eaacdd4 vendor: github.com/moby/buildkit v0.8.3 003e3c0551 pkg/signal: ignore SIGURG on all platforms 95551168ac vendor: github.com/ishidawataru/sctp f2269e66cdee387bd321445d5d300893449805be d29a55c6c3 vendor: github.com/docker/libnetwork 64b7a4574d1426139437d20e81c0b6d391130ec8 94c1890d39 builder-next: relax second cache key requirements for schema1 2a0c446866 Use v2 capabilities in layer archives Bumping docker-cli to version v20.10.7-20-ge9b8231d6a, which comprises the following commits: 8a64739631 Update Dockerfiles to latest syntax, remove "experimental" 260ba1a8a2 vendor: cpuguy83/go-md2man/v2 v2.0.1 f63cb8b97e vendor: github.com/russross/blackfriday/v2 v2.1.0 48e6b44379 Dockerfile: remove custom go build for windows/arm64 644c003606 circleCI: update docker engine to 20.10.6 0d17280a30 Jenkinsfile: update old engine version to 19.03 eedfe50a99 Jenkinsfile: update labels to prevent running on cgroups v2 f3dd1ee6c1 Fix minor wording c7cf60f657 docs: Fix wrong bridge driver option 0168626037 vendor: github.com/docker/docker-credential-helpers v0.6.4 e3a9a92b14 vendor: moby/term, Azure/go-ansiterm for golang.org/x/sys/windows compat ab733b5564 [20.10] vendor: github.com/docker/docker v20.10.7 746c553574 docs: fix link to command-line reference 2945ba4f7a Ignore SIGURG on Darwin too 032e485e1c ForwardAllSignals: check if channel is closed, and remove warning 88de81ff21 Fix `docker start` blocking on signal handling 706ca7985b Revert "[20.10] Revert "Ignore SIGURG on Linux."" 8264f5be8d docs: dockerd: fix broken link and markdown touch-ups Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* moby: update to 20.10.7Bruce Ashfield2021-07-261-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping moby to version v20.10.7-41-g013d6655bb, which comprises the following commits: 067918a8c3 [20.10] update containerd binary v1.4.8 b0da207af4 Bump go 1.16.6 (addresses CVE-2021-34558) abe8c4e80d updated vendored archive/tar to go1.16.5 7c6645b32b update archive/tar patch for go 1.16 55c363ef48 Bump go 1.16.5 8b0913935c integration: ensurePlugin: disable go modules when building plugin 09a7efb1f7 hack/ci/windows.ps1: disable go modules 6793ff26d8 pkg/fileutils: TestMatches: remove cases no longer valid for go1.16 ab9a92f79c Update test certificates 1d4a06e610 hack: add script to regenerate certificates feaca9816a hack/vendor: add check for vendored archive/tar 793340a33a [20.10] update containerd binary to v1.4.7 7429792eed docker pull: warn when pulled single-arch image does not match --platform 72b66d56a5 [20.10] vendor github.com/Microsoft/hcsshim 64a2b71405dacf76c95600f4c756a991ad09cf7c (moby branch) 50c392c9ff API: fix 404 status description on container create 025e3a7898 Update v1.41.yaml b9cf7b7db5 rootless: fix "x509: certificate signed by unknown authority" on openSUSE Tumbleweed 869b50e10b rootless: disable overlay2 if running with SELinux 44f95c7126 dockerd-rootless.sh: avoid /run/xtables.lock EACCES on SELinux hosts 78bb0f445a Dockerfile: update go-swagger to fix validation on Go1.16 618f6a79ab Run s390x tests on Ubuntu 20.04 872cb16edb update runc binary to v1.0.0 GA 4d42e18c05 vendor: swarmkit to fix deadlock in log broker 89edb68e89 Fix possible overlapping IPs 523f8b397c Jenkinsfile: skip ppc64le and s390x by default on pull requests a57fc0eb15 Fix setting swaplimit=true without checking 6474dada20 vendor: github.com/moby/buildkit v0.8.3-3-g244e8cde 895eaacdd4 vendor: github.com/moby/buildkit v0.8.3 003e3c0551 pkg/signal: ignore SIGURG on all platforms 95551168ac vendor: github.com/ishidawataru/sctp f2269e66cdee387bd321445d5d300893449805be d29a55c6c3 vendor: github.com/docker/libnetwork 64b7a4574d1426139437d20e81c0b6d391130ec8 94c1890d39 builder-next: relax second cache key requirements for schema1 2a0c446866 Use v2 capabilities in layer archives Bumping docker-cli to version v20.10.7-20-ge9b8231d6a, which comprises the following commits: 8a64739631 Update Dockerfiles to latest syntax, remove "experimental" 260ba1a8a2 vendor: cpuguy83/go-md2man/v2 v2.0.1 f63cb8b97e vendor: github.com/russross/blackfriday/v2 v2.1.0 48e6b44379 Dockerfile: remove custom go build for windows/arm64 644c003606 circleCI: update docker engine to 20.10.6 0d17280a30 Jenkinsfile: update old engine version to 19.03 eedfe50a99 Jenkinsfile: update labels to prevent running on cgroups v2 f3dd1ee6c1 Fix minor wording c7cf60f657 docs: Fix wrong bridge driver option 0168626037 vendor: github.com/docker/docker-credential-helpers v0.6.4 e3a9a92b14 vendor: moby/term, Azure/go-ansiterm for golang.org/x/sys/windows compat ab733b5564 [20.10] vendor: github.com/docker/docker v20.10.7 746c553574 docs: fix link to command-line reference 2945ba4f7a Ignore SIGURG on Darwin too 032e485e1c ForwardAllSignals: check if channel is closed, and remove warning 88de81ff21 Fix `docker start` blocking on signal handling 706ca7985b Revert "[20.10] Revert "Ignore SIGURG on Linux."" 8264f5be8d docs: dockerd: fix broken link and markdown touch-ups Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* uxen-guest-tools: inherit dos2unix to fix do_patch failureMartin Jansa2021-07-231-1/+1
| | | | | | | | | | | | | | * fixes: ERROR: uxen-guest-tools-4.1.7-r0 do_patch: Command Error: 'quilt --quiltrc /OE/build/oe-core/tmp-glibc/work/qemux86_64-oe-linux/uxen-guest-tools/4.1.7-r0/recipe-sysroot-native/etc/quiltrc push' exited with 0 Output: stdout: Applying patch fix-Makefile-for-OE-kernel-build.patch patching file Makefile Hunk #1 FAILED at 1 (different line endings). Hunk #2 FAILED at 19 (different line endings). 2 out of 2 hunks FAILED -- rejects in file Makefile Patch fix-Makefile-for-OE-kernel-build.patch does not apply (enforce with -f) Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* python3-docker-compose: Upgrade 1.29.1 -> 1.29.2Leon Anavi2021-07-201-2/+1
| | | | | | | | | | Upgrade to release 1.29.2: - Remove prompt to use docker compose in the up command - Bump py to 1.10.0 in requirements-indirect.txt Signed-off-by: Leon Anavi <leon.anavi@konsulko.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* python3-bugsnag: Upgrade 4.0.2 -> 4.1.0Leon Anavi2021-07-201-1/+1
| | | | | | | | | | | | Upgrade to release 4.1.0: - Add support for breadcrumbs. These are short log statements that are attached to error reports to help diagnose what events led to the error. - Apply filtering with params_filters to bytes, not just strings Signed-off-by: Leon Anavi <leon.anavi@konsulko.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker: Fix for sysvinitLeon Anavi2021-07-201-1/+2
| | | | | | | | | Fix for rare legacy systems which still use simultaneously both sysvinit and systemd in DISTRO_FEATURES. This fix avoids issues during do_rootfs with postinstall scriptlets of ['docker-ce']. Signed-off-by: Leon Anavi <leon.anavi@konsulko.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update to v3.2.3Bruce Ashfield2021-07-201-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping libpod to version v3.2.3-2-g09e8afe3a, which comprises the following commits: 1e6fd46e9 Bump to v3.2.3 1d7ddf511 Update release notes for v3.2.3 e4c45e759 vendor containers/common@v0.38.16 cb7016224 vendor containers/buildah@v1.21.3 1a8b2a037 Fix race conditions in rootless cni setup e54a513b9 CNI-in-slirp4netns: fix bind-mount for /run/systemd/resolve/stub-resolv.conf 1469af265 Make rootless-cni setup more robust 6f9d9636a Support uid,gid,mode options for secrets bed195bf8 vendor containers/common@v0.38.15 75431a455 [CI:DOCS] podman search: clarify that results depend on implementation 37570b7b7 vendor containers/common@v0.38.14 6ecedc161 vendor containers/common@v0.38.13 8a41bf3ee [3.2] vendor containers/common@v0.38.12 2c003d978 Bump README to v3.2.2 bb2cbf0d5 Bump to v3.2.3-dev d577c44e3 Bump to v3.2.2 9f4afa1ea fix systemcontext to use correct TMPDIR 5dabff27d Scrub podman commands to use report package 647c2024e Fix volumes with uid and gid options c2dcb3ee2 Vendor in c/common v0.38.11 ba70363f6 Initial release notes for v3.2.2 a9fd54775 Fix restoring of privileged containers d5f0729b2 Fix handling of podman-remote build --device 90805fa39 Add support for podman remote build -f - . 854c27c0a Fix panic condition in cgroups.getAvailableControllers b0dc157af Fix permissions on initially created named volumes f5cdb95ee Fix building static podman-remote 1c04cfe83 add correct slirp ip to /etc/hosts 6c4ee8535 disable tty-size exec checks in system tests 6ba9617be Fix resize race with podman exec -it eb6d4b0cf Fix documentation of the --format option of podman push e5c939183 Fix systemd-resolved detection. 613f427a0 Health Check is not handled in the compat LibpodToContainerJSON 949573c5a Do not use inotify for OCICNI ab5e770c4 getContainerNetworkInfo: lock netNsCtr before sync b957bff8b [NO TESTS NEEDED] Create /etc/mtab with the correct ownership 6d394f0e4 Create the /etc/mtab file if does not exists 879d66e7d [v3.2] cp: do not allow dir->file copying 6f769bc0e create: support images with invalid platform 19a89db66 vendor containers/common@v0.38.10 e5c070baf logs: k8s-file: restore poll sleep 4d9a9149d logs: k8s-file: fix spurious error logs dac2d31a2 utils: move message from warning to debug 60752b320 Bump to v3.2.2-dev Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* containerd: update to v1.5.2 latestBruce Ashfield2021-07-201-1/+1
| | | | | | | | | | | | | | | | | Bumping containerd to version v1.5.2-18-g9be04c276, which comprises the following commits: 78b95dff2 update runc binary to v1.0.0 GA a2dc682f1 sandbox: send pod UID to CNI plugins as K8S_POD_UID 9d8880816 content/local: inline sys.StatATimeAsTime() 3735a7dfe Fix incorrect UA used for registry authentication 31ecdf77d Fix cleanup context of teardownPodNetwork b441ec19f Add proper Go version before project checks d31f5e6b6 fix invalid validation error checking 3fd01c4ea Change Wrapf of non-error to an actual error cba7b44b6 windows: Use GetFinalPathNameByHandle for ResolveSymbolicLink 354f729a4 Prepare release notes for v1.5.2 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>