From df4dd6cf819425b845c87b2b1cadce20d034f496 Mon Sep 17 00:00:00 2001 From: "flowzone-app[bot]" <124931076+flowzone-app[bot]@users.noreply.github.com> Date: Wed, 1 Nov 2023 12:23:56 +0000 Subject: [PATCH] v4.1.2 --- .versionbot/CHANGELOG.yml | 71 +++++++++++++++++++++++++++++++++++++++ CHANGELOG.md | 17 ++++++++++ VERSION | 2 +- 3 files changed, 89 insertions(+), 1 deletion(-) diff --git a/.versionbot/CHANGELOG.yml b/.versionbot/CHANGELOG.yml index 3091b966..cdbf67da 100644 --- a/.versionbot/CHANGELOG.yml +++ b/.versionbot/CHANGELOG.yml @@ -1,3 +1,74 @@ +- commits: + - subject: Update layers/meta-balena to 1f878fc282e911950df09d5af3eb6b61a12d6c48 + hash: 3f4aacfe145168f975d4b476714c9b48a4bcfd13 + body: Update layers/meta-balena + footer: + Changelog-entry: Update layers/meta-balena to 1f878fc282e911950df09d5af3eb6b61a12d6c48 + changelog-entry: Update layers/meta-balena to 1f878fc282e911950df09d5af3eb6b61a12d6c48 + author: Self-hosted Renovate Bot + nested: + - commits: + - subject: "flasher: remove user mode check after programming keys" + hash: 05d3d41323c20f557a773229766afaef1dbf1eb5 + body: > + This check is now done in the cryptsetup initramfs hook rather + than + + during installation, which obviates the need to perform it during setup. + + Remove it. + footer: + Change-type: patch + change-type: patch + Signed-off-by: Joseph Kogut + signed-off-by: Joseph Kogut + author: Joseph Kogut + nested: [] + - subject: "initrdscripts: unlock LUKS partitions only in user mode" + hash: 63672541fefde9643040a555ba125e0bd021dc46 + body: > + During installation, some firmwares may allow keys to be + enrolled but + + fail to tip the system into user mode until the system is rebooted. We + + don't want to mislead users with only full-disk encryption into thinking + + their system also has secure boot enabled when it doesn't. + + + Disable the hook to unlock encrypted partitions if the firmware fails to + + boot into user mode. + footer: + Change-type: patch + change-type: patch + Signed-off-by: Joseph Kogut + signed-off-by: Joseph Kogut + author: Joseph Kogut + nested: [] + - subject: "os-helpers: add secure boot helpers" + hash: c8e0369c239b229366278d5d7725bfcd2e8ac86d + body: > + We now have several places where secure boot specific + configuration is + + checked. Create an os-helpers-secureboot package to consolidate and + + reuse this code. + footer: + Change-type: patch + change-type: patch + Signed-off-by: Joseph Kogut + signed-off-by: Joseph Kogut + author: Joseph Kogut + nested: [] + version: meta-balena-4.1.2 + title: "" + date: 2023-11-01T08:29:33.877Z + version: 4.1.2 + title: "" + date: 2023-11-01T12:23:48.420Z - commits: - subject: Update contracts to 109179385bb4b862cd7572be14d4c5edddbd93c9 hash: b30933af37a7eb27b3d14bfd907ea648eef2a99c diff --git a/CHANGELOG.md b/CHANGELOG.md index b625e66c..cb9aba0a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,23 @@ # Change Log ----------- +# v4.1.2 +## (2023-11-01) + + +
+ Update layers/meta-balena to 1f878fc282e911950df09d5af3eb6b61a12d6c48 [Self-hosted Renovate Bot] + +> ## meta-balena-4.1.2 +> ### (2023-11-01) +> +> * flasher: remove user mode check after programming keys [Joseph Kogut] +> * initrdscripts: unlock LUKS partitions only in user mode [Joseph Kogut] +> * os-helpers: add secure boot helpers [Joseph Kogut] +> + +
+ # v4.1.1+rev1 ## (2023-10-26) diff --git a/VERSION b/VERSION index 8580c3f2..cd9b8f55 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -4.1.1+rev1 \ No newline at end of file +4.1.2 \ No newline at end of file