3183 Commits
Author SHA1 Message Date
renovate[bot] ece5bb5d79 Update mikepenz/action-junit-report action to v6.6.0 (#5076)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-06 11:14:27 +02:00
renovate[bot] 49a69427ee Update release-drafter/release-drafter action to v7.9.0 (#5077)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-06 11:14:09 +02:00
renovate[bot] c9f178c0dd Linux: Update kernel to 6.18.55 (#5063)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.55

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 16:41:15 +02:00
Jan Čermák c7a66f90a4 Run OVA build and tests for Renovate OS bumps (#5071)
* Run OVA build and tests for Renovate OS bumps

Add a workflow that calls build.yaml to build the OVA image and run the
tests for same-repo PRs labeled run-ova-test. Renovate adds the label to
kernel, OS Agent and tempio bumps.

Pass build.yaml inputs to scripts through environment variables so a
caller's input can't inject code into the scripts. Fail on an unknown
release channel.

* Don't inherit secrets for PR build

This will generate a self-signed RAUC bundle, which is not an issue as
it's not used in the tests.
2026-10-05 14:24:11 +02:00
Jan Čermák b7cb2fdc7f Match Renovate titles to our conventions for tempio and tests (#5074)
Change default titles of Renovate bumps to "Update tempio to ..." for
tempio and "Tests: update <dep> to ..." for dependencies in tests, so it
matches patterns we used previously.
2026-10-05 13:20:58 +02:00
Jan Čermák 3b9ccad5e0 Keep kernel updates to one release per Renovate PR (#5072)
Set rebaseWhen to never for the mainline kernel group. Renovate then
leaves an open kernel PR at its version and does not move it to a
newer release. The next PR opens once the open one is merged.

The kernel.org datasource lists only the latest release of each
series. When a PR from 6.18.53 to 6.18.54 is moved to 6.18.55, the
notes can link only the 6.18.55 changelog, and the 6.18.54 one is
lost. A single release per bump also makes it easier to bisect
regressions.
2026-10-05 13:19:20 +02:00
renovate[bot] d756e82b1a Update tempio to v2026.07.0 (#5067)
Full changelog:
* https://github.com/home-assistant/tempio/releases/tag/2026.07.0
* https://github.com/home-assistant/tempio/releases/tag/2026.05.0
* https://github.com/home-assistant/tempio/releases/tag/2024.11.2
* https://github.com/home-assistant/tempio/releases/tag/2024.11.1
* https://github.com/home-assistant/tempio/releases/tag/2024.11.0

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 12:28:27 +02:00
renovate[bot] 448f0b7a98 Tests: update labgrid to v26.0 (#5068)
Full changelog:
* https://github.com/labgrid-project/labgrid/releases/tag/v26.0

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 12:23:03 +02:00
Jan Čermák 71d1f11bd4 Show the full new version in Renovate update titles (#5070)
Renovate shortens the version to the major number for major updates.
A bump of tempio to 2026.07.0 got the title "Update dependency
home-assistant/tempio to v2026". Use Renovate's default
commitMessageExtra without its isMajor branch so the commit subject
and PR title always name the full version.
2026-10-05 11:10:07 +02:00
Jan Čermák 13345d895a Add release note links to Renovate commit messages (#5066)
* Add release note links to Renovate commit messages

Put the kernel ChangeLog link and the OS Agent release links in the
commit body, as in the manual updates. For OS Agent, list every
release included in the bump.

* List release notes also for tempio and labgrid
2026-10-05 11:09:57 +02:00
renovate[bot] e975b5b740 Update shogo82148/actions-upload-release-asset action to v1.10.6 (#5064)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 09:21:38 +02:00
f1fb4c0511 Move dependency updates from Dependabot to Renovate (#5045)
* Move dependency updates from Dependabot to Renovate

* Keep GitHub Actions pinned to commit SHAs

* Track tempio and the XenServer guest utilities

* Apply batched suggestions from code review

Co-authored-by: Jan Čermák <sairon@users.noreply.github.com>

---------

Co-authored-by: Stefan Agner <stefan@agner.ch>
Co-authored-by: Jan Čermák <sairon@users.noreply.github.com>
2026-10-05 09:06:00 +02:00
Jan Čermák 07710329bc Refill boot tries before slot selection in U-Boot scripts (#5054)
* Refill boot tries before slot selection in U-Boot scripts

When no slot had tries left, the boot scripts reset both counters to 3,
stored the env and rebooted right away. On USB disks the write can sit
in the drive's cache. U-Boot never flushes it and the RPi bootloader
cuts USB power on reboot. The write is lost and the board loops
forever.

Refill the counters before the slot loop instead, so the board boots in
the same pass. The branch after the loop now only stores the
decremented counters and resets. This replaces the ODROID-N2 approach
from #4832, which kept the store and reset.

Fixes #4886

* Re-add slots dropped from BOOT_ORDER when refilling tries

RAUC removes a slot from BOOT_ORDER when it marks it bad. If the
remaining slot then used up all its tries, the refill only retried that
slot and never the other one. Append any missing slot to BOOT_ORDER when
refilling, keeping the current order so the preferred slot is still
tried first.
2026-10-01 22:35:27 +02:00
Jan Čermák 58df80a5e2 Update to Docker v29.8.2, containerd v2.3.6 (#5056)
* buildroot 8c39950771...de21723663 (3):
  > package/docker-engine: security bump to v29.8.2
  > package/docker-cli: bump version to v29.8.2
  > package/containerd: security bump to v2.3.6
2026-10-01 16:28:36 +02:00
Jan Čermák 6db153442f Disable EROFS deduplication on all boards (#5055)
Global data deduplication in mkfs.erofs is hit by an upstream bug [1].
Drop BR2_TARGET_ROOTFS_EROFS_DEDUPE from all defconfigs until it is
fixed. Rootfs images may get slightly larger, but we should have enough
headroom now.

[1] https://github.com/erofs/erofs-utils/issues/57
2026-10-01 16:15:15 +02:00
Jan Čermák c8f5b7e4a7 Disable UAS on RPi for Argon ONE M.2 (ASMedia 174c:1156) (#5051)
The USB/SATA bridge in the Argon ONE M.2 case is reported to hang in UAS
mode under heavier writes, freezing the system. Forcing it to use
usb-storage instead resolves the issue.

Fixes #5049
2026-10-01 14:55:01 +02:00
Jan Čermák 1d4f428ea7 Merge branch 'main' into dev 2026-09-30 09:45:24 +02:00
Jan Čermák fe28431711 Add RTL8761CU Bluetooth controller firmware (#5047)
Since 6.18.53, btrtl driver is used for binding RTL8761CU, requiring the
firmware as well. Add it to BR2_PACKAGE_LINUX_FIRMWARE_RTL_87XX_BT
symbol.

* buildroot d2b75e0548...8c39950771 (1):
  > package/linux-firmware: add RTL8761CU Bluetooth firmware

Needs #5046, fixes #5026
2026-09-29 23:23:23 +02:00
Jan Čermák 54f953beeb Linux: Update kernel to 6.18.54 (#5046)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.53
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.54
2026-09-29 23:22:56 +02:00
Willy Schott 6c605473ef Disable UAS for ASMedia ASM235CM (UGREEN 70499 CM300) (#5035)
UGREEN 70499 2.5 Inch SATA External Hard Drive Enclosure CM300

ID 174c:235c ASMedia Technology Inc. Ugreen Storage Device
2026-09-29 08:18:19 +02:00
dependabot[bot] dd665a6517 Bump docker/build-push-action from 7.3.0 to 7.4.0 (#5033)
Signed-off-by: dependabot[bot] <support@github.com>
2026-09-24 19:14:37 +02:00
dependabot[bot] 50a025ad65 Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 (#5032)
Signed-off-by: dependabot[bot] <support@github.com>
2026-09-23 11:11:54 +02:00
Jan Čermák b22f929d3b Bump OS to release version 18.3 18.3 2026-09-17 17:22:02 +02:00
Jan Čermák 2eb456845b Bump OS to pre-release version 18.3.rc2 18.3.rc2 2026-09-16 14:38:58 +02:00
Jan Čermák 981568d119 Linux: Update kernel to 6.18.52 (#5012)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.52

(cherry picked from commit 3019c7fe87)
2026-09-16 14:38:25 +02:00
Stefan Agner f0a92308f9 Bump OS Agent to v1.14.0 (#5011)
This release makes the agent only load AppArmor profiles whose name
matches the profile file name. Profiles are enumerated with
`apparmor_parser --names` before load/unload, and any profile which is
not the file's base name or a child profile/hat of it is rejected. This
prevents an add-on supplied apparmor.txt from redefining unrelated
profiles such as docker-default or hassio-supervisor.

Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.14.0

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit d049a3159b)
2026-09-16 14:38:25 +02:00
Jan Čermák 7816f057c0 Linux: Update kernel to 6.18.51 (#5010)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.51

(cherry picked from commit 4168cf57fd)
2026-09-16 14:38:24 +02:00
Jan Čermák d4b13b2dc0 Bump Buildroot to 2025.02.18 (#5009)
* ../buildroot 2af73e052f...d2b75e0548 (1):
  > Merge tag '2025.02.18' into 2025.02.x-haos

(cherry picked from commit ccb0f28f78)
2026-09-16 14:38:23 +02:00
Jan Čermák 5bb57c4788 Linux: Update kernel to 6.18.50 (#5007)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.50

(cherry picked from commit f395a24d90)
2026-09-16 14:38:22 +02:00
Jan Čermák 3019c7fe87 Linux: Update kernel to 6.18.52 (#5012)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.52
2026-09-15 15:11:42 +02:00
Stefan AgnerandClaude Fable 5.1 d049a3159b Bump OS Agent to v1.14.0 (#5011)
This release makes the agent only load AppArmor profiles whose name
matches the profile file name. Profiles are enumerated with
`apparmor_parser --names` before load/unload, and any profile which is
not the file's base name or a child profile/hat of it is rejected. This
prevents an add-on supplied apparmor.txt from redefining unrelated
profiles such as docker-default or hassio-supervisor.

Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.14.0

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 14:25:28 +02:00
Jan Čermák 4168cf57fd Linux: Update kernel to 6.18.51 (#5010)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.51
2026-09-14 08:55:12 +02:00
Jan Čermák ccb0f28f78 Bump Buildroot to 2025.02.18 (#5009)
* ../buildroot 2af73e052f...d2b75e0548 (1):
  > Merge tag '2025.02.18' into 2025.02.x-haos
2026-09-14 08:55:03 +02:00
Jan Čermák 9a555a8fb0 Bump OS to development version 18.4.dev0 2026-09-14 08:54:45 +02:00
Jan Čermák f395a24d90 Linux: Update kernel to 6.18.50 (#5007)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.50
2026-09-10 11:02:10 +02:00
Jan Čermák baf26d29df Bump OS to pre-release version 18.3.rc1 18.3.rc1 2026-09-09 12:03:15 +02:00
Jan Čermák 2f2d458d2a Update Go to v1.26.8 (#4998)
* buildroot 5035249eae...2af73e052f (3):
  > package/go: bump to version 1.26.8
  > package/go: security bump to version 1.26.6
  > package/go: decrease debug level for CGO linking
2026-09-04 01:05:18 +02:00
Jan Čermák 17be397e27 Linux: Update kernel to 6.18.49 (#4996)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.49
2026-09-03 15:42:37 +02:00
Jan Čermák ae3c483b9e Bump Buildroot to 2025.02.17 (#4997)
* buildroot 7b12acaaf5...5035249eae (1):
  > Merge tag '2025.02.17' into 2025.02.x-haos
2026-09-03 15:07:10 +02:00
Stefan AgnerandClaude Fable 5 4b71253ed9 Force filesystem sync when unpacking container image layers (#4994)
containerd fsyncs its metadata database when committing a snapshot, but
never syncs the unpacked layer data itself. On an unclean shutdown
within the writeback window after an image pull this leaves layers with
zero-byte files (correct names/modes/mtimes, no data) while the
snapshot stays durably recorded as valid. Because existing snapshots
are never re-verified or re-unpacked, such corruption even survives
deleting and re-pulling the image, and with shared base layers it can
only be recovered by wiping the Docker storage entirely.

This is the failure signature behind a growing number of reports of
broken plugins/add-ons/Core after power loss (e.g. 0-byte coredns in
home-assistant/plugin-dns#207, supervisor#6476/#6835, #4913).

Enable the containerd diff-service sync_fs option (containerd >= 2.0,
containerd/containerd#10284): the daemon then issues one syncfs(2) per
applied layer, making unpacked data as durable as the metadata that
references it. It applies to all clients of the daemon, including
dockerd with the containerd image store.

Verified in QEMU on haos 18.3.dev (Docker 29.6.2, containerd 2.2.6):

* With completely stock settings, a power cut <1s after `docker pull`
  of the DNS plugin image corrupts the image 2 out of 2 runs: one run
  zeroed /usr/bin/coredns entirely, the other zeroed the s6 scripts
  and left coredns truncated (20021248 of 25919650 bytes) - matching
  the two damage profiles reported in plugin-dns#207.
* Deterministic A/B with kernel background writeback suppressed, so
  survival can only come from the stack syncing explicitly: without
  this option 1215 zero-byte files including a 0-byte coredns failing
  with "exec format error"; with sync_fs the image survives intact
  (152 kB dirty at the power cut vs 76 MB).
* strace on containerd confirms 0 syncfs calls per image load before,
  one per layer after - which also confirms dockerd pulls route
  through the containerd daemon's diff service where this option
  takes effect.
* Cost of loading+unpacking the 2 GB Core image: 41.6s -> 42.2s on a
  fast disk, 226s -> 230s (+1.9%) on a 30 MB/s / 250 IOPS throttled
  disk. Note QEMU throttling does not model SD-card sync latency, so
  the real-world cost on the slowest cards may be somewhat higher, but
  it stays bounded at one syncfs per layer.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-02 17:17:22 +02:00
dependabot[bot] 832af7ea22 Bump mikepenz/action-junit-report from 6.4.2 to 6.5.0 (#4992)
Bumps [mikepenz/action-junit-report](https://github.com/mikepenz/action-junit-report) from 6.4.2 to 6.5.0.
- [Release notes](https://github.com/mikepenz/action-junit-report/releases)
- [Commits](https://github.com/mikepenz/action-junit-report/compare/d9f48fc87bc235f7e214acf696ca5abc0a986f16...a9170d5795813c01ab4901ffb045b52bab4ab09d)

---
updated-dependencies:
- dependency-name: mikepenz/action-junit-report
  dependency-version: 6.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 17:19:04 +02:00
dependabot[bot] 98cabf7e24 Bump hadolint/hadolint-action from 3.4.0 to 3.5.0 (#4991)
Bumps [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) from 3.4.0 to 3.5.0.
- [Release notes](https://github.com/hadolint/hadolint-action/releases)
- [Commits](https://github.com/hadolint/hadolint-action/compare/2a66e89f53d0771bb131a7fa31f3136336094aa6...06be81baf89a55ffd0e24b8f04a4185738dd3387)

---
updated-dependencies:
- dependency-name: hadolint/hadolint-action
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 17:18:34 +02:00
Jan Čermák 42ea0f6070 Bump OS Agent to v1.13.0 (#4990)
This release implements DBus API for NTP server configuration, building
on #4988 and required for home-assistant/supervisor#6278.

Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.13.0
2026-08-30 22:15:26 +02:00
Jan Čermák e6d5dc0110 Persist timesyncd config in /etc/systemd/timesyncd.conf.d (#4988)
The persistent timesyncd configuration is a single bind-mounted file
over /etc/systemd/timesyncd.conf. The NTP configuration through OS Agent
(home-assistant/os-agent#207) attempted to do atomic updates, but a
temporary file cannot be created next to it in the read-only
/etc/systemd, and replacing the file in the overlay directly changes the
inode, so the bind mount keeps pointing to the old content. Also, a
persisted copy of the whole file means changes to the shipped defaults
never reach existing installations.

Bind-mount the /etc/systemd/timesyncd.conf.d directory from the overlay
instead and keep the shipped timesyncd.conf read-only. Configuration is
layered as drop-ins, from lowest priority to higher:

* 10-ntp.conf (in /run): NTP servers from DHCP
* 20-custom.conf: timesyncd.conf imported from the CONFIG partition
* 50-os-agent.conf: NTP servers set through the OS Agent D-Bus API

On upgrade, settings from the previously persisted timesyncd.conf other
than the shipped defaults are moved to 20-custom.conf. This migration
can be removed later (with #4986). 50-os-agent.conf should be only
managed by OS Agent, so we don't need to care about user's edits.
Finally, if needed, drop-ins with higher priorities can be added for
complex customizations.

Refs home-assistant/supervisor#6278
2026-08-28 18:52:41 +02:00
Jan Čermák c01edb7c1c Linux: Update kernel to 6.18.48 (#4989)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.47
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.48
2026-08-28 18:52:09 +02:00
Stefan AgnerandClaude Fable 5 d846fdb13b Enable autofs support explicitly (#4984)
Supervisor pairs every network mount with a systemd .automount unit,
so the kernel automounter is a hard requirement for network storage.

Today the option is only enabled as a side effect: Buildroot's systemd
package force-enables CONFIG_AUTOFS_FS through its kernel config
fixups. That works — it even overrode the explicit disable the
Raspberry Pi config carried until 11.2 — but nothing in our configs
states the dependency, and the fixup skips symbols already set to =m,
which leaves the Rockchip boards (Green, ODROID-M1/M1S) with autofs as
a module while every other board has it built in.

Set the option in the shared fragment to document the requirement and
build it in everywhere.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-27 16:01:46 +02:00
Jan Čermák 9d696bf15f Bump OS Agent to v1.12.0 (#4983)
This release adds ScheduleDockerStorageReset method to the D-Bus API
(refs home-assistant/supervisor#6555).

Full changelog:
* https://github.com/home-assistant/os-agent/releases/tag/1.12.0
2026-08-26 16:16:31 +02:00
Jan Čermák 3eef46e270 Add service to reset Docker storage when requested (#4982)
Corrupted Docker image layers cannot be always fixed by removing and
re-pulling a single image, because layers are shared between images. The
only (easy) way to recover is wiping all of Docker's storage which is
currently cumbersome and requires OS shell access.

Add service triggered by /mnt/data/docker/.wipe-scheduled flag file
which wipes the Docker directory by atomically renaming it and deleting
synchronously. If this is interrupted, docker-prepare script removes the
leftovers before Docker is started on every boot.

It should be noted that docker-prepare also forces the switch to
containerd snapshotter after the wipe.

Refs home-assistant/supervisor#6555
2026-08-26 10:30:50 +02:00
Jan Čermák 0c4fa6a3a9 Linux: Update kernel to 6.18.46 (#4978)
* https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.18.46
2026-08-24 15:52:13 +02:00
dependabot[bot] 5425e7d0d4 Bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#4980)
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c...37fe631027851001ddb9b187196cc803df7f5f0e)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-24 15:34:59 +02:00