Compare commits
No commits in common. "rawhide" and "f36" have entirely different histories.
9 changed files with 51 additions and 406 deletions
6
.gitignore
vendored
6
.gitignore
vendored
|
|
@ -1,3 +1,3 @@
|
|||
/chrony-4.8-tar-gz-asc.txt
|
||||
/chrony-4.8.tar.gz
|
||||
/clknetsim-6ee99f50dec8.tar.gz
|
||||
/chrony-4.3.tar.gz
|
||||
/chrony-4.3-tar-gz-asc.txt
|
||||
/clknetsim-f00531.tar.gz
|
||||
|
|
|
|||
|
|
@ -1,194 +0,0 @@
|
|||
commit 03875f1ea5c4c0eeeb30a7d1fc5fdd53236f4ac2
|
||||
Author: Miroslav Lichvar <mlichvar@redhat.com>
|
||||
Date: Tue Oct 21 14:06:38 2025 +0200
|
||||
|
||||
sys_linux: allow ioctl(TCGETS2) in seccomp filter
|
||||
|
||||
Add TCGETS2 to the list of allowed ioctls. It seems to be called by the
|
||||
latest glibc version from isatty(), which is called from libpcsclite
|
||||
used by gnutls in an NTS-KE session.
|
||||
|
||||
Include the linux termios header instead of glibc header to get a usable
|
||||
definition of TCGETS2.
|
||||
|
||||
diff --git a/sys_linux.c b/sys_linux.c
|
||||
index ca5540f2..e20e459d 100644
|
||||
--- a/sys_linux.c
|
||||
+++ b/sys_linux.c
|
||||
@@ -48,7 +48,7 @@
|
||||
#ifdef FEAT_SCFILTER
|
||||
#include <sys/prctl.h>
|
||||
#include <seccomp.h>
|
||||
-#include <termios.h>
|
||||
+#include <linux/termios.h>
|
||||
#ifdef FEAT_PPS
|
||||
#include <linux/pps.h>
|
||||
#endif
|
||||
@@ -615,7 +615,7 @@ SYS_Linux_EnableSystemCallFilter(int level, SYS_ProcessContext context)
|
||||
const static int fcntls[] = { F_GETFD, F_SETFD, F_GETFL, F_SETFL };
|
||||
|
||||
const static unsigned long ioctls[] = {
|
||||
- FIONREAD, TCGETS, TIOCGWINSZ,
|
||||
+ FIONREAD, TCGETS, TCGETS2, TIOCGWINSZ,
|
||||
#if defined(FEAT_PHC) || defined(HAVE_LINUX_TIMESTAMPING)
|
||||
PTP_EXTTS_REQUEST, PTP_SYS_OFFSET,
|
||||
#ifdef PTP_PIN_SETFUNC
|
||||
commit 3c39afa13c769452d4c340bfc987e229b7c9caeb
|
||||
Author: Miroslav Lichvar <mlichvar@redhat.com>
|
||||
Date: Wed Oct 22 10:53:11 2025 +0200
|
||||
|
||||
sys_linux: fix building with older compilers and some archs
|
||||
|
||||
The recent replacement of <termios.h> with <linux/termios.h> to get
|
||||
TCGETS2 seems to work only with compilers (or C standards) that allow
|
||||
the same structure to be defined multiple times. There is a conflict
|
||||
between <sys/ioctl.h> and <linux/termios.h>.
|
||||
|
||||
Another problem is that TCGETS2 is not used on some archs like ppc64.
|
||||
|
||||
Switch back to <termios.h> and move TCGETS2 to a list in a separate
|
||||
file where it can be compiled without <sys/ioctl.h>.
|
||||
|
||||
Fixes: 03875f1ea5c4 ("sys_linux: allow ioctl(TCGETS2) in seccomp filter")
|
||||
|
||||
diff --git a/configure b/configure
|
||||
index 195b1ed7..ca64475d 100755
|
||||
--- a/configure
|
||||
+++ b/configure
|
||||
@@ -808,6 +808,7 @@ then
|
||||
# a time and the async resolver would block the main thread
|
||||
priv_ops="NAME2IPADDRESS RELOADDNS"
|
||||
EXTRA_LIBS="$EXTRA_LIBS -lseccomp"
|
||||
+ EXTRA_OBJECTS="$EXTRA_OBJECTS sys_linux_scmp.o"
|
||||
fi
|
||||
|
||||
if [ "x$priv_ops" != "x" ]; then
|
||||
diff --git a/sys_linux.c b/sys_linux.c
|
||||
index e20e459d..89eec950 100644
|
||||
--- a/sys_linux.c
|
||||
+++ b/sys_linux.c
|
||||
@@ -48,7 +48,7 @@
|
||||
#ifdef FEAT_SCFILTER
|
||||
#include <sys/prctl.h>
|
||||
#include <seccomp.h>
|
||||
-#include <linux/termios.h>
|
||||
+#include <termios.h>
|
||||
#ifdef FEAT_PPS
|
||||
#include <linux/pps.h>
|
||||
#endif
|
||||
@@ -63,6 +63,7 @@
|
||||
#endif
|
||||
|
||||
#include "sys_linux.h"
|
||||
+#include "sys_linux_scmp.h"
|
||||
#include "sys_timex.h"
|
||||
#include "conf.h"
|
||||
#include "local.h"
|
||||
@@ -615,7 +616,7 @@ SYS_Linux_EnableSystemCallFilter(int level, SYS_ProcessContext context)
|
||||
const static int fcntls[] = { F_GETFD, F_SETFD, F_GETFL, F_SETFL };
|
||||
|
||||
const static unsigned long ioctls[] = {
|
||||
- FIONREAD, TCGETS, TCGETS2, TIOCGWINSZ,
|
||||
+ FIONREAD, TCGETS, TIOCGWINSZ,
|
||||
#if defined(FEAT_PHC) || defined(HAVE_LINUX_TIMESTAMPING)
|
||||
PTP_EXTTS_REQUEST, PTP_SYS_OFFSET,
|
||||
#ifdef PTP_PIN_SETFUNC
|
||||
@@ -728,6 +729,14 @@ SYS_Linux_EnableSystemCallFilter(int level, SYS_ProcessContext context)
|
||||
SCMP_A1(SCMP_CMP_EQ, ioctls[i])) < 0)
|
||||
goto add_failed;
|
||||
}
|
||||
+
|
||||
+ /* Allow selected ioctls that need to be specified in a separate
|
||||
+ file to avoid conflicting headers (e.g. TCGETS2) */
|
||||
+ for (i = 0; SYS_Linux_GetExtraScmpIoctl(i) != 0; i++) {
|
||||
+ if (seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(ioctl), 1,
|
||||
+ SCMP_A1(SCMP_CMP_EQ, SYS_Linux_GetExtraScmpIoctl(i))) < 0)
|
||||
+ goto add_failed;
|
||||
+ }
|
||||
}
|
||||
|
||||
if (seccomp_load(ctx) < 0)
|
||||
diff --git a/sys_linux_scmp.c b/sys_linux_scmp.c
|
||||
new file mode 100644
|
||||
index 00000000..a907a97d
|
||||
--- /dev/null
|
||||
+++ b/sys_linux_scmp.c
|
||||
@@ -0,0 +1,44 @@
|
||||
+/*
|
||||
+ chronyd/chronyc - Programs for keeping computer clocks accurate.
|
||||
+
|
||||
+ **********************************************************************
|
||||
+ * Copyright (C) Miroslav Lichvar 2025
|
||||
+ *
|
||||
+ * This program is free software; you can redistribute it and/or modify
|
||||
+ * it under the terms of version 2 of the GNU General Public License as
|
||||
+ * published by the Free Software Foundation.
|
||||
+ *
|
||||
+ * This program is distributed in the hope that it will be useful, but
|
||||
+ * WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ * General Public License for more details.
|
||||
+ *
|
||||
+ * You should have received a copy of the GNU General Public License along
|
||||
+ * with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
||||
+ *
|
||||
+ **********************************************************************
|
||||
+
|
||||
+ =======================================================================
|
||||
+
|
||||
+ Lists of values that are needed in seccomp filters but need to
|
||||
+ be compiled separately from sys_linux.c due to conflicting headers.
|
||||
+ */
|
||||
+
|
||||
+#include <linux/termios.h>
|
||||
+
|
||||
+#include "sys_linux_scmp.h"
|
||||
+
|
||||
+unsigned long
|
||||
+SYS_Linux_GetExtraScmpIoctl(int index)
|
||||
+{
|
||||
+ const unsigned long ioctls[] = {
|
||||
+#ifdef TCGETS2
|
||||
+ /* Conflict between <linux/termios.h> and <sys/ioctl.h> */
|
||||
+ TCGETS2,
|
||||
+#endif
|
||||
+ 0
|
||||
+ };
|
||||
+
|
||||
+ return ioctls[index];
|
||||
+}
|
||||
diff --git a/sys_linux_scmp.h b/sys_linux_scmp.h
|
||||
new file mode 100644
|
||||
index 00000000..62a9d548
|
||||
--- /dev/null
|
||||
+++ b/sys_linux_scmp.h
|
||||
@@ -0,0 +1,28 @@
|
||||
+/*
|
||||
+ chronyd/chronyc - Programs for keeping computer clocks accurate.
|
||||
+
|
||||
+ **********************************************************************
|
||||
+ * Copyright (C) Miroslav Lichvar 2025
|
||||
+ *
|
||||
+ * This program is free software; you can redistribute it and/or modify
|
||||
+ * it under the terms of version 2 of the GNU General Public License as
|
||||
+ * published by the Free Software Foundation.
|
||||
+ *
|
||||
+ * This program is distributed in the hope that it will be useful, but
|
||||
+ * WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
+ * General Public License for more details.
|
||||
+ *
|
||||
+ * You should have received a copy of the GNU General Public License along
|
||||
+ * with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
||||
+ *
|
||||
+ **********************************************************************
|
||||
+
|
||||
+ =======================================================================
|
||||
+
|
||||
+ Header file for lists that are needed in seccomp filters but need to
|
||||
+ be compiled separately from sys_linux.c due to conflicting headers.
|
||||
+ */
|
||||
+
|
||||
+extern unsigned long SYS_Linux_GetExtraScmpIoctl(int index);
|
||||
|
|
@ -1,18 +0,0 @@
|
|||
diff -up chrony-4.7/examples/chronyd.service.servicedirs chrony-4.7/examples/chronyd.service
|
||||
--- chrony-4.7/examples/chronyd.service.servicedirs 2025-06-11 15:06:19.000000000 +0200
|
||||
+++ chrony-4.7/examples/chronyd.service 2025-07-10 12:06:57.354215498 +0200
|
||||
@@ -10,7 +10,13 @@ Type=notify
|
||||
PIDFile=/run/chrony/chronyd.pid
|
||||
Environment="OPTIONS="
|
||||
EnvironmentFile=-/etc/sysconfig/chronyd
|
||||
-ExecStart=/usr/sbin/chronyd -n $OPTIONS
|
||||
+ExecStart=!/usr/sbin/chronyd -n $OPTIONS
|
||||
+
|
||||
+User=chrony
|
||||
+LogsDirectory=chrony
|
||||
+LogsDirectoryMode=0750
|
||||
+StateDirectory=chrony
|
||||
+StateDirectoryMode=0750
|
||||
|
||||
CapabilityBoundingSet=~CAP_AUDIT_CONTROL CAP_AUDIT_READ CAP_AUDIT_WRITE
|
||||
CapabilityBoundingSet=~CAP_BLOCK_SUSPEND CAP_KILL CAP_LEASE CAP_LINUX_IMMUTABLE
|
||||
158
chrony.spec
158
chrony.spec
|
|
@ -1,5 +1,5 @@
|
|||
%global _hardened_build 1
|
||||
%global clknetsim_ver 6ee99f50dec8
|
||||
%global clknetsim_ver f00531
|
||||
%bcond_without debug
|
||||
%bcond_without nts
|
||||
|
||||
|
|
@ -8,27 +8,23 @@
|
|||
%endif
|
||||
|
||||
Name: chrony
|
||||
Version: 4.8
|
||||
Release: 3%{?dist}
|
||||
Version: 4.3
|
||||
Release: 1%{?dist}
|
||||
Summary: An NTP client/server
|
||||
|
||||
License: GPL-2.0-only
|
||||
URL: https://chrony-project.org
|
||||
Source0: https://chrony-project.org/releases/chrony-%{version}%{?prerelease}.tar.gz
|
||||
Source1: https://chrony-project.org/releases/chrony-%{version}%{?prerelease}-tar-gz-asc.txt
|
||||
Source2: https://chrony-project.org/gpgkey-8F375C7E8D0EE125A3D3BD51537E2B76F7680DAC.asc
|
||||
License: GPLv2
|
||||
URL: https://chrony.tuxfamily.org
|
||||
Source0: https://download.tuxfamily.org/chrony/chrony-%{version}%{?prerelease}.tar.gz
|
||||
Source1: https://download.tuxfamily.org/chrony/chrony-%{version}%{?prerelease}-tar-gz-asc.txt
|
||||
Source2: https://chrony.tuxfamily.org/gpgkey-8F375C7E8D0EE125A3D3BD51537E2B76F7680DAC.asc
|
||||
Source3: chrony.dhclient
|
||||
Source4: chrony.sysusers
|
||||
# simulator for test suite
|
||||
Source10: https://gitlab.com/chrony/clknetsim/-/archive/master/clknetsim-%{clknetsim_ver}.tar.gz
|
||||
Source10: https://github.com/mlichvar/clknetsim/archive/%{clknetsim_ver}/clknetsim-%{clknetsim_ver}.tar.gz
|
||||
%{?gitpatch:Patch0: chrony-%{version}%{?prerelease}-%{gitpatch}.patch.gz}
|
||||
|
||||
# add distribution-specific bits to DHCP dispatcher
|
||||
Patch1: chrony-nm-dispatcher-dhcp.patch
|
||||
# let systemd create /var/lib/chrony and /var/log/chrony
|
||||
Patch2: chrony-servicedirs.patch
|
||||
# update seccomp filter for new glibc
|
||||
Patch3: chrony-seccomp.patch
|
||||
|
||||
BuildRequires: libcap-devel libedit-devel nettle-devel pps-tools-devel
|
||||
BuildRequires: gcc gcc-c++ make bison systemd gnupg2
|
||||
|
|
@ -38,8 +34,8 @@ BuildRequires: gcc gcc-c++ make bison systemd gnupg2
|
|||
%{?systemd_requires}
|
||||
%{?sysusers_requires_compat}
|
||||
|
||||
# Needed by the leapseclist directive in default chrony.conf
|
||||
Requires: tzdata
|
||||
# Old NetworkManager expects the dispatcher scripts in a different place
|
||||
Conflicts: NetworkManager < 1.20
|
||||
|
||||
# suggest drivers for hardware reference clocks
|
||||
Suggests: ntp-refclock
|
||||
|
|
@ -58,22 +54,20 @@ service to other computers in the network.
|
|||
%prep
|
||||
%{gpgverify} --keyring=%{SOURCE2} --signature=%{SOURCE1} --data=%{SOURCE0}
|
||||
%setup -q -n %{name}-%{version}%{?prerelease} -a 10
|
||||
%{?gitpatch:%patch -P 0 -p1}
|
||||
%patch -P 1 -p1 -b .nm-dispatcher-dhcp
|
||||
%patch -P 2 -p1 -b .servicedirs
|
||||
%patch -P 3 -p1 -b .seccomp
|
||||
%{?gitpatch:%patch0 -p1}
|
||||
%patch1 -p1 -b .nm-dispatcher-dhcp
|
||||
|
||||
%{?gitpatch: echo %{version}-%{gitpatch} > version.txt}
|
||||
|
||||
# review changes in packaged configuration files and scripts
|
||||
md5sum -c <<-EOF | (! grep -v 'OK$')
|
||||
5530d6e60f84b76c27495485d2510bac examples/chrony-wait.service
|
||||
3f2ddca6065c3e8f4565d7422739795a examples/chrony.conf.example2
|
||||
b40117b4aac846d31e4ad196dc44cda3 examples/chrony-wait.service
|
||||
2d01b94bc1a7b7fb70cbee831488d121 examples/chrony.conf.example2
|
||||
96999221eeef476bd49fe97b97503126 examples/chrony.keys.example
|
||||
6a3178c4670de7de393d9365e2793740 examples/chrony.logrotate
|
||||
c3992e2f985550739cd1cd95f98c9548 examples/chrony.nm-dispatcher.dhcp
|
||||
4e85d36595727318535af3387411070c examples/chrony.nm-dispatcher.onoffline
|
||||
607c82f56639486f52c31105632909eb examples/chronyd.service
|
||||
5ddbb8a8055f587cb6b0b462ca73ea46 examples/chronyd-restricted.service
|
||||
2b81c60c020626165ac655b2633608eb examples/chrony.nm-dispatcher.onoffline
|
||||
677ad16d6439daa369da44a1b75d1772 examples/chronyd.service
|
||||
EOF
|
||||
|
||||
# don't allow packaging without vendor zone
|
||||
|
|
@ -81,23 +75,21 @@ test -n "%{vendorzone}"
|
|||
|
||||
# use example chrony.conf as the default config with some modifications:
|
||||
# - use our vendor zone (2.*pool.ntp.org names include IPv6 addresses)
|
||||
# - enable leapseclist to get TAI-UTC offset and leap seconds
|
||||
# - enable leapsectz to get TAI-UTC offset and leap seconds from tzdata
|
||||
# - enable keyfile
|
||||
# - use NTP servers from DHCP
|
||||
sed -e 's|^\(pool \)\(pool.ntp.org\)|\12.%{vendorzone}\2|' \
|
||||
-e 's|#\(leapseclist\)|\1|' \
|
||||
-e 's|#\(leapsectz\)|\1|' \
|
||||
-e 's|#\(keyfile\)|\1|' \
|
||||
-e 's|^pool.*pool.ntp.org.*|&\n\n# Use NTP servers from DHCP.\nsourcedir /run/chrony-dhcp|' \
|
||||
< examples/chrony.conf.example2 > chrony.conf
|
||||
|
||||
touch -r examples/chrony.conf.example2 chrony.conf
|
||||
|
||||
# set selinux context in chronyd-restricted service
|
||||
sed -i '/^ExecStart/a SELinuxContext=system_u:system_r:chronyd_restricted_t:s0' \
|
||||
examples/chronyd-restricted.service
|
||||
|
||||
# regenerate the file from getdate.y
|
||||
rm -f getdate.c
|
||||
|
||||
mv clknetsim-*-%{clknetsim_ver}* test/simulation/clknetsim
|
||||
mv clknetsim-%{clknetsim_ver}* test/simulation/clknetsim
|
||||
|
||||
%build
|
||||
%configure \
|
||||
|
|
@ -108,7 +100,6 @@ mv clknetsim-*-%{clknetsim_ver}* test/simulation/clknetsim
|
|||
--chronyrundir=/run/chrony \
|
||||
--docdir=%{_docdir} \
|
||||
--with-ntp-era=$(date -d '1970-01-01 00:00:00+00:00' +'%s') \
|
||||
--with-chronyc-user=chrony \
|
||||
--with-user=chrony \
|
||||
--with-hwclockfile=%{_sysconfdir}/adjtime \
|
||||
--with-pidfile=/run/chrony/chronyd.pid \
|
||||
|
|
@ -130,6 +121,8 @@ mkdir -p $RPM_BUILD_ROOT{%{_unitdir},%{_prefix}/lib/systemd/ntp-units.d}
|
|||
|
||||
install -m 644 -p chrony.conf $RPM_BUILD_ROOT%{_sysconfdir}/chrony.conf
|
||||
|
||||
install -m 640 -p examples/chrony.keys.example \
|
||||
$RPM_BUILD_ROOT%{_sysconfdir}/chrony.keys
|
||||
install -m 755 -p %{SOURCE3} \
|
||||
$RPM_BUILD_ROOT%{_sysconfdir}/dhcp/dhclient.d/chrony.sh
|
||||
install -m 644 -p examples/chrony.logrotate \
|
||||
|
|
@ -137,8 +130,6 @@ install -m 644 -p examples/chrony.logrotate \
|
|||
|
||||
install -m 644 -p examples/chronyd.service \
|
||||
$RPM_BUILD_ROOT%{_unitdir}/chronyd.service
|
||||
install -m 644 -p examples/chronyd-restricted.service \
|
||||
$RPM_BUILD_ROOT%{_unitdir}/chronyd-restricted.service
|
||||
install -m 755 -p examples/chrony.nm-dispatcher.onoffline \
|
||||
$RPM_BUILD_ROOT%{_prefix}/lib/NetworkManager/dispatcher.d/20-chrony-onoffline
|
||||
install -m 755 -p examples/chrony.nm-dispatcher.dhcp \
|
||||
|
|
@ -153,7 +144,6 @@ cat > $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig/chronyd <<EOF
|
|||
OPTIONS="%{?with_seccomp:-F 2}"
|
||||
EOF
|
||||
|
||||
touch $RPM_BUILD_ROOT%{_sysconfdir}/chrony.keys
|
||||
touch $RPM_BUILD_ROOT%{_localstatedir}/lib/chrony/{drift,rtc}
|
||||
|
||||
echo 'chronyd.service' > \
|
||||
|
|
@ -161,7 +151,7 @@ echo 'chronyd.service' > \
|
|||
|
||||
%check
|
||||
# set random seed to get deterministic results
|
||||
export CLKNETSIM_RANDOM_SEED=24508
|
||||
export CLKNETSIM_RANDOM_SEED=24505
|
||||
%make_build -C test/simulation/clknetsim
|
||||
make quickcheck
|
||||
|
||||
|
|
@ -179,20 +169,20 @@ if test -a %{_libexecdir}/chrony-helper; then
|
|||
sed 's|.*|server &|' < $f > /run/chrony-dhcp/"${f##*servers.}.sources"
|
||||
done 2> /dev/null
|
||||
fi
|
||||
%systemd_post chronyd.service chronyd-restricted.service chrony-wait.service
|
||||
%systemd_post chronyd.service chrony-wait.service
|
||||
|
||||
%preun
|
||||
%systemd_preun chronyd.service chronyd-restricted.service chrony-wait.service
|
||||
%systemd_preun chronyd.service chrony-wait.service
|
||||
|
||||
%postun
|
||||
%systemd_postun_with_restart chronyd.service chronyd-restricted.service
|
||||
%systemd_postun_with_restart chronyd.service
|
||||
|
||||
%files
|
||||
%{!?_licensedir:%global license %%doc}
|
||||
%license COPYING
|
||||
%doc FAQ NEWS README examples/chrony.keys.example
|
||||
%doc FAQ NEWS README
|
||||
%config(noreplace) %{_sysconfdir}/chrony.conf
|
||||
%ghost %config %attr(640,root,chrony) %{_sysconfdir}/chrony.keys
|
||||
%config(noreplace) %verify(not md5 size mtime) %attr(640,root,chrony) %{_sysconfdir}/chrony.keys
|
||||
%config(noreplace) %{_sysconfdir}/logrotate.d/chrony
|
||||
%config(noreplace) %{_sysconfdir}/sysconfig/chronyd
|
||||
%{_sysconfdir}/dhcp/dhclient.d/chrony.sh
|
||||
|
|
@ -203,94 +193,12 @@ fi
|
|||
%{_unitdir}/chrony*.service
|
||||
%{_sysusersdir}/chrony.conf
|
||||
%{_mandir}/man[158]/%{name}*.[158]*
|
||||
%ghost %dir %attr(750,chrony,chrony) %{_localstatedir}/lib/chrony
|
||||
%dir %attr(750,chrony,chrony) %{_localstatedir}/lib/chrony
|
||||
%ghost %attr(-,chrony,chrony) %{_localstatedir}/lib/chrony/drift
|
||||
%ghost %attr(-,chrony,chrony) %{_localstatedir}/lib/chrony/rtc
|
||||
%ghost %dir %attr(750,chrony,chrony) %{_localstatedir}/log/chrony
|
||||
%dir %attr(750,chrony,chrony) %{_localstatedir}/log/chrony
|
||||
|
||||
%changelog
|
||||
* Tue Oct 21 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.8-3
|
||||
- update seccomp filter for new glibc (#2405310)
|
||||
|
||||
* Mon Sep 08 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.8-2
|
||||
- drop root privileges in chronyc by default
|
||||
|
||||
* Wed Aug 27 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.8-1
|
||||
- update to 4.8
|
||||
|
||||
* Thu Aug 14 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.8-0.1.pre1
|
||||
- update to 4.8-pre1
|
||||
|
||||
* Wed Jul 23 2025 Fedora Release Engineering <releng@fedoraproject.org> - 4.7-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Thu Jul 10 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.7-2
|
||||
- let systemd create /var/lib/chrony and /var/log/chrony (#2372944)
|
||||
- drop workaround for broken build on aarch64
|
||||
- drop old conflict with NetworkManager
|
||||
|
||||
* Wed Jun 11 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.7-1
|
||||
- update to 4.7
|
||||
|
||||
* Thu May 22 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.7-0.2.pre1
|
||||
- add workaround for broken build on aarch64
|
||||
|
||||
* Wed May 21 2025 Miroslav Lichvar <mlichvar@redhat.com> 4.7-0.1.pre1
|
||||
- update to 4.7-pre1
|
||||
|
||||
* Thu Jan 16 2025 Fedora Release Engineering <releng@fedoraproject.org> - 4.6.1-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Tue Oct 08 2024 Miroslav Lichvar <mlichvar@redhat.com> 4.6.1-1
|
||||
- update to 4.6.1
|
||||
|
||||
* Mon Sep 02 2024 Miroslav Lichvar <mlichvar@redhat.com> 4.6-1
|
||||
- update to 4.6
|
||||
|
||||
* Tue Jul 30 2024 Miroslav Lichvar <mlichvar@redhat.com> 4.6-0.1.pre1
|
||||
- update to 4.6-pre1
|
||||
|
||||
* Wed Jul 17 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.5-4
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
|
||||
|
||||
* Tue Jan 23 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.5-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Fri Jan 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.5-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Tue Dec 05 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.5-1
|
||||
- update to 4.5
|
||||
|
||||
* Wed Nov 22 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.5-0.1.pre1
|
||||
- update to 4.5-pre1
|
||||
|
||||
* Wed Aug 09 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.4-1
|
||||
- update to 4.4
|
||||
- require tzdata (#2218368)
|
||||
|
||||
* Wed Jul 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 4.4-0.4.pre2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
||||
* Wed Jun 21 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.4-0.3.pre2
|
||||
- update to 4.4-pre2
|
||||
- set selinux context in chronyd-restricted service (#2169949)
|
||||
|
||||
* Tue Jun 06 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.4-0.2.pre1
|
||||
- rebuild for AES-GCM-SIV in new nettle
|
||||
|
||||
* Wed May 10 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.4-0.1.pre1
|
||||
- update to 4.4-pre1
|
||||
- switch from patchX to patch -P X
|
||||
|
||||
* Wed Jan 25 2023 Miroslav Lichvar <mlichvar@redhat.com> 4.3-3
|
||||
- drop default chrony.keys config (#2104918)
|
||||
- add chronyd-restricted service for minimal NTP client configurations
|
||||
- convert license tag to SPDX
|
||||
|
||||
* Wed Jan 18 2023 Fedora Release Engineering <releng@fedoraproject.org> - 4.3-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
|
||||
|
||||
* Wed Aug 31 2022 Miroslav Lichvar <mlichvar@redhat.com> 4.3-1
|
||||
- update to 4.3
|
||||
|
||||
|
|
|
|||
1
ci.fmf
1
ci.fmf
|
|
@ -1 +0,0 @@
|
|||
resultsdb-testcase: separate
|
||||
21
gating.yaml
21
gating.yaml
|
|
@ -1,25 +1,16 @@
|
|||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_context: bodhi_update_push_testing
|
||||
decision_contexts: [bodhi_update_push_testing]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
|
||||
#Rawhide
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}
|
||||
|
||||
# rawhide
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_context: bodhi_update_push_stable
|
||||
decision_contexts: [bodhi_update_push_stable]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
|
||||
#gating rhel
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- rhel-*
|
||||
decision_context: osci_compose_gate
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: osci.brew-build./plans/tier1-public.functional}
|
||||
- !PassingTestCaseRule {test_case_name: osci.brew-build./plans/tier1-internal.functional}
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}
|
||||
|
|
|
|||
47
plans.fmf
47
plans.fmf
|
|
@ -1,47 +0,0 @@
|
|||
/tier1-internal:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/tier1/internal
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream, fedora
|
||||
because: They don't have access to internal repos.
|
||||
|
||||
/tier1-public:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/tier1/public
|
||||
|
||||
/tier2-tier3-internal:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/tier2-tier3/internal
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream, fedora
|
||||
because: They don't have access to internal repos.
|
||||
|
||||
/tier2-tier3-public:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/tier2-tier3/public
|
||||
|
||||
/others-internal:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/others/internal
|
||||
adjust:
|
||||
enabled: false
|
||||
when: distro == centos-stream, fedora
|
||||
because: They don't have access to internal repos.
|
||||
|
||||
/others-public:
|
||||
plan:
|
||||
import:
|
||||
url: https://gitlab.com/redhat/centos-stream/tests/chrony.git
|
||||
name: /plans/others/public
|
||||
6
plans/ci.fmf
Normal file
6
plans/ci.fmf
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
summary: Test plan that runs all tests from tests repo.
|
||||
discover:
|
||||
how: fmf
|
||||
url: https://src.fedoraproject.org/tests/chrony.git
|
||||
execute:
|
||||
how: tmt
|
||||
6
sources
6
sources
|
|
@ -1,3 +1,3 @@
|
|||
SHA512 (chrony-4.8-tar-gz-asc.txt) = df7f4e06f74a4b8c9a49e8fe57ea02e0324c5683d036412c32192a09f08e08f33537609cef8df0b4302bfcd63332b3092f33f40c8d02857c93ecea13822b5b47
|
||||
SHA512 (chrony-4.8.tar.gz) = 949b796bb34db32a5c1b9e6b53be6a22e51c59f24a316d585b8a52a52ab1f61bdf0378dc58b282bb0ba4fac1f05e1e99fbe37cb4259aa2b359e7bf679c176aab
|
||||
SHA512 (clknetsim-6ee99f50dec8.tar.gz) = 2621d1c44b84b42fcdf644f236ff90dab9f8a8407a138c8719c53dd9c4f21480db3b4ba598116aa1b9d6bd1fa02fc410d85a43baf55ddf8ad47fc09aba4c4477
|
||||
SHA512 (chrony-4.3.tar.gz) = 1394bac3ed684352fe89b7fef7da50e61f9f522abee807627ae1fc4c2dde891017bc8e5b13759fced028f3a1e875d5e4e5a4f85de65c63b5f83d0ca03bb4c5df
|
||||
SHA512 (chrony-4.3-tar-gz-asc.txt) = 300b06f253ac3727edb86a1b7c337f9529ee752bbb471b266217b6a8ac5183e827264177a3210d436425d746673bf11fbdc41da145673213e28165197c6c76b7
|
||||
SHA512 (clknetsim-f00531.tar.gz) = a44f543574519d1d5b5778f91b88fc73a976de511b97011c8ff3bc61a7ebff868fe9c6b46947ff4b58b29bd45520ffa68147934b1d289b1ffada4a329c048df5
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue