Rolf Neugebauer
dcc4a5e799
kernel: Update to 4.17.4/4.14.53/4.9.111/4.4.139
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-07-03 11:49:36 +01:00
Rolf Neugebauer
9f1f99026d
kernel: Update to 4.16.17/4.14.51/4.4.138
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-06-22 10:01:18 +01:00
Rolf Neugebauer
ef5c128a8c
kernel: Update to 4.4.137
...
Somehow I missed this kernel update when it happened...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-06-21 16:17:29 +01:00
Rolf Neugebauer
6b629fa30b
kernel: Tweak 4.4.x kernel config file
...
Add new (disabled) option CONFIG_CC_OPTIMIZE_FOR_PERFORMANCE
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-06-07 13:54:53 +01:00
Rolf Neugebauer
4e830a35a1
kernel: Update to 4.16.14/4.14.48/4.9.107/4.4.136
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-06-07 12:10:22 +01:00
Rolf Neugebauer
ba5e75a24e
kernel: Update to 4.14.47/4.9.105/4.4.135
...
These releases are a single patch only, fixing a bug.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-06-06 08:26:54 +01:00
Rolf Neugebauer
acc059e6c8
kernel: Updatr to 4.16.13/4.14.46/4.9.104/4.4.134
...
Note, we skip 4.14.45 because 4.14.46 only has 3 patches
in it which unbreak 'perf' compilation.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-05-30 15:59:03 +01:00
Rolf Neugebauer
d9a1ea45ce
kernel: Update to 4.16.12/4.14.44/4.9.103/4.4.133
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-05-30 14:36:14 +01:00
Rolf Neugebauer
c4a265c77f
kernel: Update to 4.16.9/4.14.41/4.9.100/4.4.132
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-05-16 17:55:10 +01:00
Rolf Neugebauer
be8929da30
kernel: Fix SCTP kernel config
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-05-03 18:48:02 +01:00
Rolf Neugebauer
655bb391ca
kernel: Update to 4.16.7/4.14.39/4.9.98/4.4.131
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-05-03 17:22:26 +01:00
Sukchan Lee
aa7d5fc942
kernel: SCTP support
...
Enable SCTP protocol as a kernel module
Signed-off-by: Sukchan Lee <acetcom@gmail.com >
2018-05-01 23:04:29 +09:00
Rolf Neugebauer
7a4233dec5
kernel: Add USB storage support for x86_64 and arm64
...
This is useful for some baremetal configs, such as using
USB sticks on a RPi3. I enabled it for x86_64 as well
to keep the differences smaller.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-04-30 10:35:33 +01:00
Rolf Neugebauer
262b25f874
kernel: Update to 4.16.6/4.14.38/4.9.97/4.4.130
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-04-30 10:35:33 +01:00
Rolf Neugebauer
f1046b9a29
kernel: Adjust 4.4.x kernel config
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-04-27 18:52:12 +01:00
Rolf Neugebauer
54ed15ccce
kernel: Update to 4.16.5/4.14.37/4.9.96/4.4.129
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-04-27 16:45:36 +01:00
Rolf Neugebauer
054b9bb924
kernel: Update to 4.9.94/4.4.128
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-04-14 11:18:33 +01:00
Rolf Neugebauer
4454c7b854
kernel: Enable MPLS_ROUTING and MPLS_IPTUNNEL as modules
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-04-13 15:21:57 +01:00
Rolf Neugebauer
fa9452af09
kernel: Update to 4.15.16/4.14.33/4.9.93/4.4.127
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-04-09 10:35:34 +01:00
Rolf Neugebauer
a5a685750d
kernel: Update to 4.15.15/4.14.32/4.9.92/4.4.126
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-04-01 17:52:14 +01:00
Rolf Neugebauer
462961d5c9
kernel: Update to 4.15.14/4.14.31/4.9.91/4.4.125
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-03-30 13:29:03 +01:00
Rolf Neugebauer
7f12cb577a
kernel: Update to 4.15.13/4.14.30/4.9.90/4.4.124
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-03-30 12:19:02 +01:00
Rolf Neugebauer
9cb6f2d802
kernel: Enable CONFIG_FB_EFI for x86_64 and arm64
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-03-30 12:18:31 +01:00
Rolf Neugebauer
208811355a
kernel: Update to 4.15.12/4.14.29/4.9.89/4.4.123
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@gmail.com >
2018-03-22 19:55:57 +00:00
Rolf Neugebauer
45b613e668
kernel: Update to 4.15.11/4.14.28/4.9.88/4.4.122
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-03-20 12:05:27 +00:00
Rolf Neugebauer
513e368880
kernel: Enable CEPH, DRBD, and RBD
...
All enabled as modules
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-03-15 13:50:18 +00:00
Rolf Neugebauer
659f877da6
kernel: Update to 4.15.9/4.14.26/4.9.87/4.4.121
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-03-12 17:00:06 +00:00
Rolf Neugebauer
ae30674227
kernel: Update to 4.14.24/4.9.86/4.4.120
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-03-09 12:39:11 +00:00
Rolf Neugebauer
fcba3e2350
kernel: Update to 4.15.7/4.4.23/4.9.85/4.4.119
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-28 11:02:15 +00:00
Rolf Neugebauer
afd255d6c9
kernel: Adjust 4.4.x config file
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-26 14:37:44 +00:00
Rolf Neugebauer
75ac2563f5
kernel: Update to 4.15.6/4.14.22/4.9.84/4.4.118
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-26 12:16:51 +00:00
Rolf Neugebauer
5c68ca489d
kernel: Update to 4.15.5/4.14.21/4.9.83/4.4.117
...
Also remove the 4.4 patch which should have been removed by
231cead2cc ("kernel: Update to 4.15.4/4.14.20/4.9.82/4.4.116")
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-23 18:06:18 +00:00
Rolf Neugebauer
231cead2cc
kernel: Update to 4.15.4/4.14.20/4.9.82/4.4.116
...
The 4.14.20 update has Meltdown/Spectre fixes for arm64
The 4.4.116 update incorporates the proper fix for the
div by zero crash in the firmware loader, so the patch
with the hackish workaround was dropped.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-19 14:06:11 +00:00
Rolf Neugebauer
334334cea9
kernel: Adjust 4.4 kernel config
...
The CONFIG_BPF_JIT_ALWAYS_ON option has now been back-ported
to 4.4.115 as well. Enable it.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-06 18:43:34 +00:00
Rolf Neugebauer
ee0f182014
kernel: Update to 4.15.1/4.14.17/4.9.80/4.4.115
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-06 18:06:25 +00:00
Rolf Neugebauer
a6a5f69c8d
kernel: Update to 4.14.16/4.9.79/4.4.114
...
The 4.14 and 4.9 kernels have a significant number of
fixes to eBPF and also a fix for kernel level sockets
and namespace removals, ie fixes some aspects of
https://github.com/moby/moby/issues/5618
"unregister_netdevice: waiting for lo to become free"
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-02-06 13:23:40 +00:00
Rolf Neugebauer
183fcf0970
kernel: Add new retpoline option to the x86 4.4.x kernel
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-24 12:32:15 +00:00
Rolf Neugebauer
5de66f4fd9
kernel: Update to 4.14.15/4.9.78/4.4.113
...
While at it, also update to latest alpine base
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-24 11:56:34 +00:00
Rolf Neugebauer
130c6222bb
kernel: Adjust kernel config with new options
...
- Enable RETPOLINE by default. Note, however, this will
only be used if the compiler supports it.
- Enable sysfs interface for vulnerabilities
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-17 14:36:30 +00:00
Rolf Neugebauer
bfceb1dfbb
kernel: Update to 4.14.14/4.9.77/4.4.112
...
The 4.4.14 has a number of important fixes/additions:
- New support for retpolines (enabled but requires newer gcc
to take advantage of). This provides mitigation for Spectre
style attacks.
- Various KPTI fixes including fixes for EFI booting
- More eBPF fixes around out-of-bounds and overflow of
maps. These were used for variant 1 of CVE-2017-5753.
- Several KVM related to CVE-2017-5753, CVE-2017-5715,
CVE-2017-17741.
- New sysfs interface listing vulnerabilities:
/sys/devices/system/cpu/vulnerabilities
The 4.9.77 kernel also has seems to have most/all of the above
back-ported.
See https://lwn.net/SubscriberLink/744287/1fc3c18173f732e7/
for more details on the Spectre mitigation.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-17 14:31:54 +00:00
Rolf Neugebauer
9a101d1136
kernel: Update to 4.14.13/4.9.76/4.4.111
...
This looks like there are a couple of minor fixes to the
recent KPTI changes but nothing major...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-10 11:12:27 +00:00
Rolf Neugebauer
682f6d8819
kernel: Enable KPTI on 4.9.x and 4.4.x kernels
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-06 11:24:43 +00:00
Rolf Neugebauer
d86d43fe40
kernel: Update to 4.14.12/4.9.75/4.4.110
...
4.9.75 and 4.4.10 now have KPTI backported as well
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-06 10:00:13 +00:00
Rolf Neugebauer
7abc1df0ad
kernel: Update to 4.14.11/4.9.74/4.4.109
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2018-01-03 11:03:52 +00:00
Rolf Neugebauer
dfb1982c65
kernel: Update to 4.14.9/4.9.72/4.4.108
...
This contains the fixes to the eBPF verifier which allowed
privilege escalation in 4.9 and 4.14 kernels.
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-28 16:43:14 +00:00
Rolf Neugebauer
e140ab4acc
kernel: Update to 4.14.8/4.9.71/4.4.107
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-28 14:48:20 +00:00
Rolf Neugebauer
467c1af0e2
kernel: Update to 4.14.7/4.9.70/4.4.106
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-18 16:59:21 +00:00
Rolf Neugebauer
6a15459665
kernel: Update to 4.14.5/4.9.68/4.4.105
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-11 11:24:38 +00:00
Rolf Neugebauer
53127d7209
kernel: Update to 4.14.4/4.9.67/4.4.104
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-06 10:11:50 +00:00
Rolf Neugebauer
3ed38c59f4
kernel: Update to 4.14.3/4.9.66/4.4.103
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-12-01 15:28:09 +00:00