Skip to content

Synchronise 2025.1 with upstream#17

Merged
priteau merged 1 commit into
stackhpc/2025.1from
upstream/2025.1-2026-06-22
Jun 22, 2026
Merged

Synchronise 2025.1 with upstream#17
priteau merged 1 commit into
stackhpc/2025.1from
upstream/2025.1-2026-06-22

Conversation

@github-actions

Copy link
Copy Markdown

This PR contains a snapshot of 2025.1 from upstream stable/2025.1.

Pipes the new agent flag (enable_bios_bootloader_install) to agents.
This flag disables bootloader install (calls to grub-install) by default
for security reasons.

Part of mitigation of CVE-2026-43003.

Changes to backported versions: The default flips to avoid breaking
stable users of Ironic. While this is a less secure default, it allows
operators to apply the patch without fear of breaking existing
workloads. Operators who need the increased security posture should
explicitly set [agent]/enable_bios_bootloader_install to False.

Related-Bug: 2148310
Change-Id: I694bbe121e09e7e0b2e6c5ab3746f7943385190a
Signed-off-by: Clif Houck <me@clifhouck.com>
Signed-off-by: Jay Faulkner <jay@jvf.cc>
(cherry picked from commit e38ae0c)
@github-actions github-actions Bot requested a review from a team as a code owner June 22, 2026 08:29
@github-actions github-actions Bot added automated Automated action performed by GitHub Actions synchronisation labels Jun 22, 2026
@priteau priteau closed this Jun 22, 2026
@priteau priteau reopened this Jun 22, 2026
@priteau priteau merged commit edc8a5a into stackhpc/2025.1 Jun 22, 2026
4 checks passed
@priteau priteau deleted the upstream/2025.1-2026-06-22 branch June 22, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated action performed by GitHub Actions synchronisation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants