google-compute-engine-oslogin-32bit-20190801-lp152.5.4.1<>,SP_z=/=„qj ;2%ל<NZFߪy 0Z )XMIvt<^ UЉAh,ȸ.Nԃ@# LőPD t1<7ϷtSa؉f=).)ues)(zD蔓gmu$m~X2 tA1[J",>>I?Id&/ ; l$/ HW     Xt (88@,9,: ,>BGBHBIBXBYC \C8]CT^CbDcDdEseExfE{lE}uEvEwHxH0yHLGIhIlIrICgoogle-compute-engine-oslogin-32bit20190801lp152.5.4.1OS Login Functionality for Google Compute EngineLibraries and scripts to enable OS Login functionality for Google Compute Engine. Modifies sshd, nsswitch, and sshd_pam configurations._z=build81*xopenSUSE Leap 15.2openSUSEApache-2.0http://bugs.opensuse.orgSystem/Daemonshttps://github.com/GoogleCloudPlatform/compute-image-packageslinuxx86_64/sbin/ldconfig x * y# A큤_z=_z=_z=_z=_z=_z=_z=7626626abaa112ed6f1ff6c22004673a67fc7c882e8789d90b15e99e78a170f4a30493192832ad173bd7490090c23155804701a1a8a19b871febb74232cf6e56c0bad0d003d23d8b838bf26c752b54aeec02cfbce83464c27365af1a81a3375989622bf0d687949202a04c83ac8377f1b2d2c33d6272bddb27ac9415263fce9flibnss_cache_oslogin-20190801.00.solibnss_oslogin-20190801.00.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootgoogle-compute-engine-20190801-lp152.5.4.1.src.rpmgoogle-compute-engine-oslogin-32bitgoogle-compute-engine-oslogin-32bit(x86-32)libnss_cache_oslogin.so.2libnss_oslogin.so.2@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libcurl.so.4libgcc_s.so.1libgcc_s.so.1(GCC_3.0)libjson-c.so.3libpam.so.0libpam.so.0(LIBPAM_1.0)libpam.so.0(LIBPAM_EXTENSION_1.0)libstdc++.so.6libstdc++.so.6(CXXABI_1.3)libstdc++.so.6(CXXABI_1.3.9)libstdc++.so.6(GLIBCXX_3.4)libstdc++.so.6(GLIBCXX_3.4.11)libstdc++.so.6(GLIBCXX_3.4.14)libstdc++.so.6(GLIBCXX_3.4.15)libstdc++.so.6(GLIBCXX_3.4.21)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1^@^^]@]]x][]Ik]H@\@\P\Q\E@\[[['["X[ @[ZZ@ZԐ@ZtRZ#@YZ@YY@YY@YzYXx@XwoXWXXXX`@X`@X`@X@X@X@John Paul Adrian Glaubitz Robert Schweikert Robert Schweikert Robert Schweikert Robert Schweikert Robert Schweikert John Paul Adrian Glaubitz John Paul Adrian Glaubitz John Paul Adrian Glaubitz John Paul Adrian Glaubitz John Paul Adrian Glaubitz John Paul Adrian Glaubitz Robert Schweikert John Paul Adrian Glaubitz Robert Schweikert John Paul Adrian Glaubitz adrian.glaubitz@suse.comadrian.glaubitz@suse.comrjschwei@suse.comrjschwei@suse.comadrian.glaubitz@suse.comadrian.glaubitz@suse.comadrian.glaubitz@suse.comadrian.glaubitz@suse.comadrian.glaubitz@suse.comrjschwei@suse.comrjschwei@suse.comadrian.glaubitz@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comjengelh@inai.derjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.comrjschwei@suse.com- Don't enable and start google-network-daemon.service when it's already installed (bsc#1169978)- Add gceosl-no-def-sysgrps.patch (bsc#1170719, bsc#1170720) + Do not add the created user to the adm (CVE-2020-8903), docker (CVE-2020-8907), or lxd (CVE-2020-8933) groups if they exist (bsc#1173258)- Rename the sysctl file that applies the GCE network settings (bsc#1167810) + The file 11-gce-network-security.conf applies network configuration settings. Specifically the value for net.ipv4.conf.all.rp_filter is also part of the system defaults in /usr/lib/sysctl.d/50-default.conf and thus the default setting was applied, instead of the desired setting. As 50-default is processed after 11-gce-network-security.- Add gcei-waitlimit-dns.patch (bsc#1151398) + Add a wait limit to retrying DNS resolution to avoid a forever loop- Fix file list + On i586 Python code is also under _libdir thus creating a conflict between the packages.- Add gcei_disableipv6.patch (bsc#1150058) + Upstream introduced an interface named "DisableIpv6" but the implementation was incomplete and the interface was missing for SUSE distros- Fix install location of NSS and PAM shared libraries (bsc#1146172) - Switch RPM group for oslogin package from Hardware to System/Daemons- Add patch to normalize setup version of Python code + gcei-normalize-python-version.patch - Fix file matching patterns in %files section for oslogin package- Update to version 20190801 (bsc#1144092, bsc#1144170) + Google Compute Engine * Re-enable boto config without plugin. * Fix metadata script retrieval for python 2 and 3. + Google Compute Engine OS Login * Fix for 2FA on RHEL 8. - from version 20190730 + Google Compute Engine * Support for Debian 10. * New package versioning. * Support for Google Private Access over IPv6. * Support root disk expansion in RHEL 8 and Debian 10. + Google Compute Engine OS Login * Bug fixes for sudoers. * Initial groups support (not yet enabled). - Add patch to explicitly link NSS and PAM shared libraries against libboost_regex on SLE-12 + gcei-link-boost_regex.patch - Refresh patches for new version + gcei-scripts-after-reg.patch - Set StandardOutput=journal+console in custom systemd service files + google-optimize-local-ssd.service + google-set-multiqueue.service - Stop installing configuration file for systemd-journald + Logging is now configured through systemd service files - Update file matching patterns in %files section for new version- Update to version 20190522 (bsc#1136266, bsc#1136267) + Google Compute Engine * Fix guest attributes flow in Python 3. + Google Compute Engine OS Login * Update OS Login control file for FreeBSD support. - from version 20190521 + Google Compute Engine * Retry download for metadata scripts. * Fix script retrieval in Python 3. * Disable boto config in Python 3. * Update SSH host keys in guest attributes. * Fix XPS settings with more than 64 vCPUs.- Update to version 20190416 (bsc#1128392, bsc#1134179) + Google Compute Engine * FreeBSD fixes: syslog socket location and OS detection. * Upstart systems: only run startup scripts at boot. + Google Compute Engine OS Login * Fix pam_group ordering detection. * Restart cron from the OS Login control file. * Add PAM entry to su:account stack. - from version 20190315 + Google Compute Engine OS Login * Fix alternate challenge section for two factor authentication. * Fix FreeBSD compatibility issues in the control file. - from version 20190304 + Google Compute Engine * Set oom_score_adjust for google_accounts_daemon. + Google Compute Engine OS Login * Use pam_group to provide users with default groups. * Add compat.h to support FreeBSD. * Exit immediately after a two factor authentication failure. * Add support for Google phone prompt challenges. - Adjust paths for new upstream directory layout in %build and %install - Include systemd service file to run google_optimize_local_ssd command + google-optimize-local-ssd.service - Include systemd service file to run google_set_multiqueue command + google-set-multiqueue.service - Install journald configuration files into /usr/lib/systemd/journald.conf.d - Refresh patches for new version + gcei-hide-py-deps.patch + gcei-scripts-after-reg.patch + gcei-set-run_dir.patch- Update to version 20190124 (bsc#1123671, bsc#1123672) + Google Compute Engine * Fix metadata script retrieval to support Python 3.- Remove dropped service from systemd setup macros (bsc#1122172) - Drop use of restart_on_update, force service restart with -f option on service_del_preun and service_del_postun - Detect and handle removed services in pre rather than post- Update to version 20181206 (bsc#1119029, bsc#1119110) + Google Compute Engine * Support enabling OS Login two factor authentication. * Improve accounts support for FreeBSD. + Google Compute Engine OS Login * Support OS Login two factor authentication (Alpha). * Improve SELinux support. - from version 20181023 + Google Compute Engine * Fix: Update sudoer group membership without overriding local groups. - from version 20181018 + Google Compute Engine * Fix: Remove users from sudoers group on account removal.- Remove conditions for distributions older than Leap 42.3 and SLE 12 + Delete init scripts google-accounts-daemon.suse, google-clock-skew-daemon.suse, google-instance-setup.suse, google-network-daemon.suse, google-shutdown-scripts.suse, google-startup-scripts.suse - Fix build for distributions with gcc version less than 4.9 + Add new dependency on boost- Update to version 20181011 + Google Compute Engine * Revert: Remove users from sudoers group on account removal. - from version 20181008 + Google Compute Engine * Remove users from sudoers group on account removal. * Remove gsutil dependency for metadata scripts. - from version 20180905 + Google Compute Engine * Remove ntp package dependency. * Support Debian 10 Buster. * Restart the network daemon if networking is restarted. * Prevent setup of the default ethernet interface. * Accounts daemon verifies username is 32 characters or less. + Google Compute Engine OS Login * Add user name validation to pam modules. * Return false on failed final load. * Support FreeBSD. * Support Debian 10 Buster. - from version 20180611 + Google Compute Engine * Prevent IP forwarding daemon log spam. * Make default shell configurable when executing metadata scripts. * Rename distro directory to distro_lib. - Refresh patches for new version + gcei-set-run_dir.patch- Ensure that google-ip-forwarding-daemon service and google-network-setup are stopped and disabled during upgrade - Ensure that google-network-daemon service is enabled and started during upgrade- Add patch to set run_dir to /var/run (bsc#1097378, #1097616) + gcei-set-run_dir.patch - Drop deleted patch from spec file + gcei-lnx-distro-py3.patch- Remove gcei-lnx-distro-py3.patch + Upstream intention is to depend on distro module from GitHub - Add dependency on python3-distro for SLE/Leap 15 and later- Add patch gcei-lnx-distro-py3.patch (bsc#1094074)- Update to version 20180510 (bsc#1092214) + Prevent delay in configuring IP forwarding routes. + Improve instance setup support for FreeBSD. - Include new google-network-daemon + Add google-network-daemon.service activation in %pre and %post sections + Add google-network-daemon.suse init script for SysV - Stop shipping deprecated google-ip-forwarding-daemon service + Remove google-ip-forwarding-daemon.service activation in %pre and %post sections + Drop google-ip-forwarding-daemon.suse from source distribution - Add missing association with "init" package for %pre, %post, %preun and %postun sections - Install google_oslogin_nss_cache binary into oslogin package- Update to version 20180504 (bsc#1092214) + Create a new network daemon. + Refactor the IP forwarding daemon and network setup. + Improvements for using NSS cache in the accounts daemon. + Include libnss cache as part of the OS Login package. - Refresh patches for new version: + gcei-scripts-after-reg.patch- Update to version 20180227 (bsc#1066273) + Add distro specific logic. + Support SLES 11 and 12 in multi-nic setup. + Fix boto config documentation. + Add modprobe blacklist for nouveau and floppy modules. + Fix irqbalance conflict in Debian package. + Fix conflict with other applications that use curl and SSL. - Install new kernel module blacklist into /etc/modprobe.d. - Refresh patches for new version: + gcei-hide-py-deps.patch- Update to version 20180129 (bsc#1078349, bsc#1079077) + Improve rsyslog daemon reset when using the dhcp exit hook. + The OS Login feature is generally available. + Change the OS Login uid restriction to allow uid 1000. + Close socket connections after requesting metadata. - From version 20171213 + Force IPv4 for Debian apt configs.- Update to version 20171129 (bsc#1070895, bsc#1070918) + Generate SSH host keys when none are present. + Improve logging when activating OS Login. + Fix parsing logic for expiration time on SSH public keys. + Fix home directory creation PAM config.- Change dependencies -init depends on -oslogin + oslogin feature is now enabled by the initialization code when appropriate - Do not start the oslogin feature upon package install- Fix build for SLES 11- Update to version 20171025 (bsc#1064356, bsc#1065308) + Add apt configuration to prevent auto-removal of Google packages. + Rename set_hostname to prevent naming conflicts. + Remove logging when checking OS Login status. - From version 20171019 + Support the enable-oslogin metadata key for activating OS Login. + Improve packaging to restart services. + OS Login is available in Beta. + Add status option to the OS Login control file. - From version 20171006 + Fix system hang during VM shutdown. + JSON parser accepts string types for int64 values. - From version 20170921 + JSON parser casts uid and gid to unsigned integers. - From version 20170914 + Remove fstab barrier options in EL 7. + Use curl to download metadata script files for SSL certificate validation. + Use netifaces for retrieving MAC address names if the import exists.- Ship the udevrules with the -init package only- Fix baslibs.conf, use package, not files - Include rpmlintrc and baslibc.conf as source- Add gcei-scripts-after-reg.patch (bsc#1057671)- Update to version 20170829 (bsc#1049242, FATE#323757) + Support oslogin feature + Add rpmlintrc ~ We ship pam and nss modules in -oslogin we do not want to name the package according to the shared library naming policy + Add baslibs.config ~ Handle the nss and pam modules provided by oslogin properly - From version 20170718 + Allow nologin paths other than /sbin/nologin. + Try to download GCS URLs with curl if gsutil is not installed. + Fix control scripts to correctly restart sshd and nscd if they exist. + Retry HTTP requests if error 500 is received. + Move oslogin sudoers directory locations. - Setup for Python 3 build oSTW and SLE 15 - Source package renamed to google-compute-engine + Binary subpackages -init -oslogin- The startup script attempts a network connection, thus it must run after network setup- Scripts that are one-shot should not be marked as "stop_on_removal" as there is no process running (bsc#1017395) - One-shot scripts should not run with startproc- Update to version 20161213 (bsc#1015829, bsc#1016372) + Remove gcei-handle-failed-open.patch included upstream + Remove gcei-handle-missing-gsutil.patch included upstream + Forward port gcei-hide-py-deps.patch + Improved alias IP support - From 20161118 + Add support for alias IPs in the IP forwarding daemon. + IP forwarding daemon adds back local routes after network restart. + Account daemon removes expired key access without metadata change. + Account daemon ignores SSH keys with non-ascii characters. + Improved exception handling. + Fix for syslog startup on systemd. + Add a route to the metadata server to /etc/hosts. - From 20160930 + Provide a service to enable network interfaces on boot. + Create a common library for inspecting network interfaces. + Allow metadata script output that is not UTF-8. + Fixed instance config file logic. + Fixed accounts management Python 3 compatibility. + Fixed IP forwarding Python 3 compatibility. + Improved style consistency. + Run a service on boot to enable additional network interfaces. + Update dhclient-script on EL 6 to fix local routing.- Resolve description inaccuracy - Call %service_* just once, but with all args- Include in SLE 12 and SLE 11 (FATE#321748, FATE#321890, bsc#994943)- Update gcei-handle-failed-open.patch to match upstream PR- Add gcei-handle-failed-open.patch * Do not exit with a traceback if the sudoers file cannot be written- Package the rsyslog config unconditionally, rsyslog also available on SLE 11- Add sysvinit scripts for SUSE, upstream scripts are RHEL specific * google-accounts-daemon.suse * google-clock-skew-daemon.suse * google-instance-setup.suse * google-ip-forwarding-daemon.suse * google-shutdown-scripts.suse * google-startup-scripts.suse- Own the udev directories, fixes issue with SLE 12 build- Conflict with the previous generation of initialization code. * According to upstream and update path is not supported and has too many corner cases to reliably work. Thus running instances are not expected to upgrade.- Initial build - Version 20160803/bin/sh20190801-lp152.5.4.120190801-lp152.5.4.1securitypam_oslogin_admin.sopam_oslogin_login.solibnss_cache_oslogin-20190801.00.solibnss_cache_oslogin.so.2libnss_oslogin-20190801.00.solibnss_oslogin.so.2/lib//lib/security//usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:13321/openSUSE_Leap_15.2_Update/683e3a2cf502586260dd28f624171ecb-google-compute-engine.openSUSE_Leap_15.2_Updatedrpmxz5x86_64-suse-linuxdirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (GNU/Linux), dynamically linked, BuildID[sha1]=3ecf92077fbb520019bc299642fca6fc282557ff, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (GNU/Linux), dynamically linked, BuildID[sha1]=818298d646be2ed2df3f9ca19817ea2c1a04b6f9, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (GNU/Linux), dynamically linked, BuildID[sha1]=49eebad0b1436ba88db3888ff7d888a42e6d305d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (GNU/Linux), dynamically linked, BuildID[sha1]=3ae5d8bb6daf745ab22b48fba5abf05d9cae4a64, stripped&7RR R RRRRRR RRRRR RRR RRRR R RRRRRR RRRRR RRR RRPRRRRRRR RRRRRRR RRPRRRRRR RRRRRRR RRutf-8b18aaca729af58b20244d56e4fd3cd587b8be7370f38cf6902a723da9366688b? 7zXZ !t/?]"k%{"ytl6 7g>|.Qwʴ?T/&vBto$&HLM6 90&CVW2wrH'SH8f&o YE'v , vwLy8ۙ%nNB-;rvWU%m϶XP˹"Q)>i30輌¦Z! =>YD5` @t6J8n{Xa[`L#ƬB) ȗrȒ6 ޳&6p=#'aqQ ˆtnXi+ݲ.ik[ X>6&Fla5&J@l1R,Nc**-GxP* 윷/fX ɘ {̀d/DdU;TD`QOq麙^j}1<7pr2E|a j\Of`6 fBC%U}dQeXhm*\.aHMܴkX&'ɲ͜,˂!nADˉ^9CWn-%ŢXo2 cr%[? Gaa_?(W8X(l~W>8k۳ uKEjZRZT%s.&6%q/jl_j=1,ꎯ`=j=L!Kl](C#WΩ/y :CEy1ܡiFoM?v.0WZF  x Q<Kh;R"A<{DKPѽNd0ނ*N_>P) vFXht:O/X9l$n_{dzC1gMijgQaĕk2;,)b؁ 9C XWkTN evC GCMN(X%n֑$nw 1Js/iu &f$%_/L&=oث'xEGÉ;(L/Ln-[XE ͦM~3 W%KFN͞˻S-4t,?@O62Xj,9방գY ZpT _e+"B'k/餾D ^εkƐCT 摗LzgϜ+".gϜ0ah KCW5نvFO9 8ϛK K$