Upstream changes:
* 2.650: new Systemd Services, GRUB 2, and Kea DHCP modules; WebSocket
proxy support in Servers Index; Alpine Linux support; Let's Encrypt
IP-based certificate support; editable SSH public keys in Users and
Groups.
* 2.651: Certbot certificate request/renewal fixes; fix live activation
of Linux bond interfaces.
* 2.652: global per-user ACL to block URL downloads from non-public IPs;
fix hex HTML entity recognition; fix session checks with HMAC session
keys; fix Usermin switching to use one-time login URLs.
* 2.653: fix missing xmlrpc-lib.pl; fix partially installed Debian
package listing; Authentic theme improvements.
Recipe changes:
* Drop init-exclude.patch: both hunks (init/index.cgi commented-out
runlevel loop and init/init-lib.pl exclude= support) are now
incorporated in upstream webmin 2.653.
* Refresh net-generic.patch: upstream added alpine-linux to the
os_support line in net/module.info; refresh the patch context.
* Refresh net-lib.pl.patch: context shifted by 4 lines with fuzz 1;
refreshed against 2.653 (same fallback to debian-linux-lib.pl).
* Remove webmin-openrc-init from do_install: webmin 2.653 ships a new
webmin-openrc-init script that references /sbin/openrc-run, which is
not available on systemd-based distros; remove the file to avoid an
unresolvable RDEPENDS QA failure.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Major version jump (1.x → 2.x series). Key upstream changes:
* 2.x dropped the legacy Netdata Cloud Agent-Cloud-Link (ACLK) and
merged cloud-connectivity into the main binary; ENABLE_ACLK and
ENABLE_CLOUD cmake options removed. OpenSSL and libcurl are now
mandatory build dependencies (no longer optional via PACKAGECONFIG).
* Improved database engine, new collectors (systemd-units, OTel,
scripts plugin), and expanded Go plugin with SNMP overhaul.
* 2.10.x stabilization: fix ZFS-related crashes, eBPF shared-memory
pool leak, SNMP counter wrapping, database engine memory safety.
* 2.10.4: larger patch for stability, memory safety, and crash
resilience across database engine, streaming, and collectors;
backports new macOS hardware sensor collectors.
Recipe changes:
* Add curl and openssl to mandatory DEPENDS (both now REQUIRED by
cmake); remove PACKAGECONFIG[openssl] and PACKAGECONFIG[cloud].
* Remove webui_v0/v1/v2 PACKAGECONFIG entries and associated
do_install block (the webui architecture changed in 2.x).
* Remove -DENABLE_ACLK=OFF from EXTRA_OECMAKE (option no longer
exists); keep -DENABLE_EXPORTER_PROMETHEUS_REMOTE_WRITE=OFF.
* Refresh 0002-Do-not-hardcode-systemd-unit-directories.patch for
2.10.4 (the BUILD_FOR_PACKAGING/systemd service install blocks
shifted ~1119 lines; same substitution preserved).
* 2.x vendors its own libsensors copy which needs flex/bison to
generate its config lexer/parser at build time; add flex-native
and bison-native to DEPENDS.
* Protobuf detection now runs unconditionally (used by several 2.x
exporters/collectors even with the remote-write exporter disabled);
add protobuf and protobuf-native to DEPENDS and point cmake at the
native protoc via Protobuf_PROTOC_EXECUTABLE.
* Disable several 2.x features that reach out to the network at
configure time and cannot work in an offline build:
- ENABLE_PLUGIN_OTEL / ENABLE_PLUGIN_OTEL_SIGNAL_VIEWER (pull in
Rust/Corrosion via CMake FetchContent)
- ENABLE_PLUGIN_SCRIPTS (requires Go, same as ENABLE_PLUGIN_GO)
- ENABLE_ML (FetchContent-downloads dlib)
- ENABLE_LIBBACKTRACE (ExternalProject-downloads libbacktrace)
- ENABLE_DASHBOARD, now exposed as PACKAGECONFIG[dashboard] and
off by default (the local agent dashboard isn't shipped in the
release tarball; enabling it makes cmake fetch it from
app.netdata.cloud at configure time)
* BUILD_FOR_PACKAGING=ON now also installs sysusers.d/tmpfiles.d
snippets under ${nonarch_libdir}; remove them in do_install since
user creation is handled by useradd.bbclass and tmpfiles by our own
netdata-volatiles.conf, avoiding an "installed but not shipped" QA
failure from duplicate/unmanaged files.
* Fix three new-in-2.x reproducibility leaks that embed host build
paths into the packages (buildpaths QA, an error in oe-core's default
ERROR_QA):
- Add 0003-Do-not-record-the-configure-command-line-in-the-binar.patch:
2.x bakes the full cmake invocation into config.h for
"netdata -W buildinfo"; the collected flags include --sysroot= and
-ffile-prefix-map= and so leak ${WORKDIR} into the binary.
- Add 0004-libsensors-do-not-emit-line-directives-in-generated-s.patch:
pass bison -l / flex -L so the generated conf-parse.[ch] and
conf-lex.c do not carry absolute #line paths (these live in file
contents, so -ffile-prefix-map cannot rewrite them).
- Remove the shipped build-info-cmake-cache.gz in do_install: it is a
gzipped CMakeCache.txt kept only for buildinfo reporting and is full
of host paths.
Verified with buildpaths promoted back to ERROR_QA: netdata builds and
packages with no buildpaths diagnostics and no /home path remains
anywhere under the package tree.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
352
Shown a warning if the last shutdown/reboot was unclean
Bug fixes and translation updates
351
Firewall ports can be deleted individually
350
networking: fix renaming of bridges and other groups (RHEL-117883)
bridge: fix OpenSSH_10.2p1 host key detection
Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Remove the patch with the fix that is already present in the new
version.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
The BusyBox version of mv does not have the -Z flag for setting SELinux
security context. This results in failure
when the cockpit-certificate-helper script is executed.
Depend the package on GNU Coreutils to make sure that the proper version
of mv is installed.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
The old-bridge package config option was removed from the recipe,
but the usage of this option was left in some places.
Remove any reference to old-bridge. Only the Python bridge is currently
supported by Cockpit.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Makes the hammer a bit smaller, since we do not enable go by default
in packageconfig's it helps with yocto check layer with default config.
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Set pam module path to ${base_libdir}/security as this is the default
path in libpam.
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Add the runtime dependency Virtual/docker need when the package config
Docker is enabled. This avoids do_rootfs installs issues.
Signed-off-by: Tanguy Raufflet <tanguy.raufflet@savoirfairelinux.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Modification of the group for the apps.plugin file (from root to
netdata) and removal of execution authorization for the “others”.
This modification improves security by limiting the netdata group to
execute the plugin as root.
Signed-off-by: Tanguy Raufflet <tanguy.raufflet@savoirfairelinux.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Our provided netdata.conf contained a lot of keys which are no longer
supported by netdata. Netdata allows to regenerate the configuration
file and present all possible keys with their default values. This
refreshed file will be more easy to configure by our users.
To generate this file, I basically ran the documented command and
replaced the file paths with our variables when applicable.
Signed-off-by: Enguerrand de Ribaucourt <enguerrand.de-ribaucourt@savoirfairelinux.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Netdata now provides its own systemd service files. They provide better
hardening than the one we were defining in the recipe.
Unfortunately, the CMakeLists.txt file wants to install them into /lib
rather than /usr/lib. I added mv commands to put them in the expected
location depending on usrmerge.
Signed-off-by: Enguerrand de Ribaucourt <enguerrand.de-ribaucourt@savoirfairelinux.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Some netdata plugins like cgroups or docker require permissions to
access the docker socket in order to label data properly.
Signed-off-by: Enguerrand de Ribaucourt <enguerrand.de-ribaucourt@savoirfairelinux.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Replace references of WORKDIR with UNPACKDIR where it makes sense to do
so in preparation for changing the default value of UNPACKDIR.
Signed-off-by: Khem Raj <raj.khem@gmail.com>
* fixed a few minor oelint-adv warnings in the recipe
* placed all SRC_URI lines in one block
Tested on Raspberry PI 4
Signed-off-by: Jan Vermaete <jan.vermaete@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
In version 301, the default bridge implementation was changed to Python.
Adjust recipe to build and install new Python bridge.
Old bridge implementation is still available and can be enabled using
'--enable-old-bridge' flag. Add PACKAGECONFIG option for old bridge.
New bridge shows minor regressions like networking graph not generated
correctly. Probably additional dependencies are missing.
For this reason, keep the old bridge enabled by default.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Non-existing variable was used as a prefix for 'cockpit-askpass'.
Fix the path, so the binary will be correctly installed
in 'cockpit-bridge' package.
Fortunately, even with incorrect path, this binary was "caught"
by the main 'cockpit' package, so it was always installed in the final
image.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
libyaml dependency now required. See:
6ee42875c: Bundle libyaml
json-c also seems required now. If I don't enable it, I get compile errors.
compression and https options got renamed upstream to lz4 and openssl. See:
c74bf56ee: Code reorg and cleanup - enrichment of /api/v2
Signed-off-by: Sam Van Den Berge <sam.van.den.berge@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Apps (Applications tab) is an optional Cockpit Project package.
Make it also an optional package in recipe.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Packagekit (Software Updates tab) is an optional Cockpit Project
package. Make it also an optional package in recipe.
Signed-off-by: Daniel Semkowicz <dse@thaumatec.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>