Import of pkgsrc-2015Q2
This commit is contained in:
@@ -1,11 +1,10 @@
|
||||
# $NetBSD: Makefile,v 1.5 2015/03/13 10:27:48 spz Exp $
|
||||
# $NetBSD: Makefile,v 1.10 2015/06/23 17:45:33 bouyer Exp $
|
||||
|
||||
VERSION= 4.5.0
|
||||
VERSION= 4.5.1
|
||||
VERSION_IPXE= 9a93db3f0947484e30e753bbd61a10b17336e20e
|
||||
|
||||
DISTNAME= xen-${VERSION}
|
||||
PKGNAME= xentools45-${VERSION}
|
||||
PKGREVISION= 2
|
||||
CATEGORIES= sysutils
|
||||
MASTER_SITES= http://bits.xensource.com/oss-xen/release/${VERSION}/
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
@comment $NetBSD: PLIST,v 1.1 2015/01/20 16:42:13 bouyer Exp $
|
||||
@comment $NetBSD: PLIST,v 1.2 2015/06/23 17:45:33 bouyer Exp $
|
||||
bin/pygrub
|
||||
bin/qemu-img-xen
|
||||
bin/xen-detect
|
||||
@@ -28,6 +28,7 @@ include/libxl_event.h
|
||||
include/libxl_json.h
|
||||
include/libxl_utils.h
|
||||
include/libxl_uuid.h
|
||||
include/libxlutil.h
|
||||
include/xen/COPYING
|
||||
include/xen/arch-arm.h
|
||||
include/xen/arch-arm/hvm/save.h
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
$NetBSD: distinfo,v 1.5 2015/03/13 10:27:48 spz Exp $
|
||||
$NetBSD: distinfo,v 1.9 2015/06/23 17:45:33 bouyer Exp $
|
||||
|
||||
SHA1 (ipxe-git-9a93db3f0947484e30e753bbd61a10b17336e20e.tar.gz) = fecadf952821e830ce1a1d19655288eef8488f88
|
||||
RMD160 (ipxe-git-9a93db3f0947484e30e753bbd61a10b17336e20e.tar.gz) = 539bfa12db7054228250d6dd380bbf96c1a040f8
|
||||
Size (ipxe-git-9a93db3f0947484e30e753bbd61a10b17336e20e.tar.gz) = 2867999 bytes
|
||||
SHA1 (xen-4.5.0.tar.gz) = c4aab5fb366496ad1edc7fe0a935a0d604335637
|
||||
RMD160 (xen-4.5.0.tar.gz) = e35ba0cb484492c1a289218eb9bf53b57dbd3a45
|
||||
Size (xen-4.5.0.tar.gz) = 18404933 bytes
|
||||
SHA1 (xen-4.5.1.tar.gz) = f10328ce63625a5a7bfa3af5899c4432a467c051
|
||||
RMD160 (xen-4.5.1.tar.gz) = 4c449d799e041a52a94c00ee43a8c28fd4af1b96
|
||||
Size (xen-4.5.1.tar.gz) = 18410400 bytes
|
||||
SHA1 (patch-.._.._ipxe_src_core_settings.c) = 9e053e5e9936f49c46af0d59382a67d5f28cb39d
|
||||
SHA1 (patch-.._.._ipxe_src_interface_efi_efi_snp.c) = 7cd8a2d2dbeff55624b5d3461d22cd8331221762
|
||||
SHA1 (patch-.._.._ipxe_src_net_fcels.c) = 7c13c87af5e38233f8b867503789f536394e7005
|
||||
@@ -15,9 +15,9 @@ SHA1 (patch-.._docs_man_xl.cfg.pod.5) = e2058495b6fe85af338e22560d46996d36aeedab
|
||||
SHA1 (patch-.._docs_man_xl.conf.pod.5) = 015da24a45388468d56f1ecfa60f6acf07bdfef8
|
||||
SHA1 (patch-.._docs_man_xl.pod.1) = b194f2c5608c6f0e80a4abd8655808cf91355cd5
|
||||
SHA1 (patch-.._docs_man_xlcpupool.cfg.pod.5) = b44813af965e4d9d0d51c18b22d286736a4663b2
|
||||
SHA1 (patch-CVE-2015-2152) = 5a1cabf330b3a1bd902adf2b33dd5c4c32b8ab9d
|
||||
SHA1 (patch-Makefile) = 5d5b9678ed9764275ee95f49d24e8538a0e8a01c
|
||||
SHA1 (patch-Rules.mk) = e0dc4234c35dc2d78afad4a90b0af829a6a10b50
|
||||
SHA1 (patch-XSA135) = c27b9c495d7348864e9939f54574e3afc37a816a
|
||||
SHA1 (patch-blktap_drivers_Makefile) = 7cc53b2a0dea1694a969046ab8542271ca63f9e7
|
||||
SHA1 (patch-configure) = d1a1b9c9e00dd79bb872190282006201510ce2c1
|
||||
SHA1 (patch-examples_Makefile) = 5fe7bb876d254cf0c4f774ed0f08dcaea5b355ff
|
||||
@@ -32,7 +32,7 @@ SHA1 (patch-include_xen-sys_NetBSD_gntdev.h) = b1f60f46e606b7591d68d98655d1cb29d
|
||||
SHA1 (patch-libfsimage_common_Makefile) = 9c80a669805ba2e1f224985c71ca976fbe60e8b5
|
||||
SHA1 (patch-libfsimage_ufs_ufs.h) = ce1461ab83499edb4e127e3b7af9dfc1e9c0267f
|
||||
SHA1 (patch-libxc_xc__netbsd.c) = 547a713bbe9ddc92ee51b57a7b58a619f01225f1
|
||||
SHA1 (patch-libxl_Makefile) = 5b5dede29e5d9c579cdd7d6497f692ecf3a3c2cb
|
||||
SHA1 (patch-libxl_Makefile) = 16abc9e74855dacbeff40ad1010876dd80230977
|
||||
SHA1 (patch-libxl_libxl__create.c) = d4c94e9a389e9a7601513460f31c82e4f4bf28c9
|
||||
SHA1 (patch-libxl_libxl__save__helper.c) = 70e5237e28bea1aa87486e080fc25aa81300a6d8
|
||||
SHA1 (patch-libxl_libxl_uuid.c) = d14286be8ccdbcb5fae544a1968e7b681b63e884
|
||||
@@ -45,7 +45,7 @@ SHA1 (patch-qemu-xen-traditional_Makefile) = aac50189b3e359314c5d47745d50113f190
|
||||
SHA1 (patch-qemu-xen-traditional_block-raw-posix.c) = fb03fe527515424d72758b606ab8d2e5bf8c341b
|
||||
SHA1 (patch-qemu-xen-traditional_configure) = a29520d12c229feed85b335e9241dc085427a3db
|
||||
SHA1 (patch-qemu-xen-traditional_hw_e1000.c) = d94874baa64a0974d29c8c3a117cf0fae030952d
|
||||
SHA1 (patch-qemu-xen-traditional_hw_ide.c) = fb674b326321f4865183eee889967b1a948698e0
|
||||
SHA1 (patch-qemu-xen-traditional_hw_ide.c) = 4dc86cfec2d86766293af18b558b6bd5a336e697
|
||||
SHA1 (patch-qemu-xen-traditional_hw_pass-through.c) = b87481f764e16fb1345c44b4f46fa3837901a4e2
|
||||
SHA1 (patch-qemu-xen-traditional_hw_pass-through.h) = 0bf5cbc1d6f5506c1878296fce98ca3e42fc6560
|
||||
SHA1 (patch-qemu-xen-traditional_hw_piix4acpi.c) = 432cbbd922a2453d3aab37e49cced767a3f1ad34
|
||||
|
||||
@@ -1,42 +0,0 @@
|
||||
$NetBSD: patch-CVE-2015-2152,v 1.1 2015/03/13 10:27:49 spz Exp $
|
||||
|
||||
xsa119-unstable.patch from upstream.
|
||||
XSA-119 is "HVM qemu unexpectedly enabling emulated VGA graphics backends"
|
||||
|
||||
--- libxl/libxl_dm.c.orig 2015-01-12 16:53:24.000000000 +0000
|
||||
+++ libxl/libxl_dm.c
|
||||
@@ -180,7 +180,14 @@ static char ** libxl__build_device_model
|
||||
if (libxl_defbool_val(vnc->findunused)) {
|
||||
flexarray_append(dm_args, "-vncunused");
|
||||
}
|
||||
- }
|
||||
+ } else
|
||||
+ /*
|
||||
+ * VNC is not enabled by default by qemu-xen-traditional,
|
||||
+ * however passing -vnc none causes SDL to not be
|
||||
+ * (unexpectedly) enabled by default. This is overridden by
|
||||
+ * explicitly passing -sdl below as required.
|
||||
+ */
|
||||
+ flexarray_append_pair(dm_args, "-vnc", "none");
|
||||
|
||||
if (sdl) {
|
||||
flexarray_append(dm_args, "-sdl");
|
||||
@@ -513,7 +520,17 @@ static char ** libxl__build_device_model
|
||||
}
|
||||
|
||||
flexarray_append(dm_args, vncarg);
|
||||
- }
|
||||
+ } else
|
||||
+ /*
|
||||
+ * Ensure that by default no vnc server is created.
|
||||
+ */
|
||||
+ flexarray_append_pair(dm_args, "-vnc", "none");
|
||||
+
|
||||
+ /*
|
||||
+ * Ensure that by default no display backend is created. Further
|
||||
+ * options given below might then enable more.
|
||||
+ */
|
||||
+ flexarray_append_pair(dm_args, "-display", "none");
|
||||
|
||||
if (sdl) {
|
||||
flexarray_append(dm_args, "-sdl");
|
||||
139
sysutils/xentools45/patches/patch-XSA135
Normal file
139
sysutils/xentools45/patches/patch-XSA135
Normal file
@@ -0,0 +1,139 @@
|
||||
$NetBSD: patch-XSA135,v 1.1 2015/06/23 17:45:33 bouyer Exp $
|
||||
|
||||
pcnet: fix Negative array index read
|
||||
|
||||
From: Gonglei <arei.gonglei@huawei.com>
|
||||
|
||||
s->xmit_pos maybe assigned to a negative value (-1),
|
||||
but in this branch variable s->xmit_pos as an index to
|
||||
array s->buffer. Let's add a check for s->xmit_pos.
|
||||
|
||||
upstream-commit-id: 7b50d00911ddd6d56a766ac5671e47304c20a21b
|
||||
|
||||
Signed-off-by: Gonglei <arei.gonglei@huawei.com>
|
||||
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
||||
Reviewed-by: Jason Wang <jasowang@redhat.com>
|
||||
Reviewed-by: Jason Wang <jasowang@redhat.com>
|
||||
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
|
||||
|
||||
diff --git a/hw/pcnet.c b/hw/pcnet.c
|
||||
index 7cc0637..9f3e1cc 100644
|
||||
--- qemu-xen-traditional/hw/pcnet.c.orig
|
||||
+++ qemu-xen-traditional/hw/pcnet.c
|
||||
@@ -1250,7 +1250,7 @@ static void pcnet_transmit(PCNetState *s)
|
||||
target_phys_addr_t xmit_cxda = 0;
|
||||
int count = CSR_XMTRL(s)-1;
|
||||
int add_crc = 0;
|
||||
-
|
||||
+ int bcnt;
|
||||
s->xmit_pos = -1;
|
||||
|
||||
if (!CSR_TXON(s)) {
|
||||
@@ -1276,34 +1276,39 @@ static void pcnet_transmit(PCNetState *s)
|
||||
if (BCR_SWSTYLE(s) != 1)
|
||||
add_crc = GET_FIELD(tmd.status, TMDS, ADDFCS);
|
||||
}
|
||||
+
|
||||
+ if (s->xmit_pos < 0) {
|
||||
+ goto txdone;
|
||||
+ }
|
||||
+
|
||||
+ bcnt = 4096 - GET_FIELD(tmd.length, TMDL, BCNT);
|
||||
+ s->phys_mem_read(s->dma_opaque, PHYSADDR(s, tmd.tbadr),
|
||||
+ s->buffer + s->xmit_pos, bcnt, CSR_BSWP(s));
|
||||
+ s->xmit_pos += bcnt;
|
||||
+
|
||||
if (!GET_FIELD(tmd.status, TMDS, ENP)) {
|
||||
- int bcnt = 4096 - GET_FIELD(tmd.length, TMDL, BCNT);
|
||||
- s->phys_mem_read(s->dma_opaque, PHYSADDR(s, tmd.tbadr),
|
||||
- s->buffer + s->xmit_pos, bcnt, CSR_BSWP(s));
|
||||
- s->xmit_pos += bcnt;
|
||||
- } else if (s->xmit_pos >= 0) {
|
||||
- int bcnt = 4096 - GET_FIELD(tmd.length, TMDL, BCNT);
|
||||
- s->phys_mem_read(s->dma_opaque, PHYSADDR(s, tmd.tbadr),
|
||||
- s->buffer + s->xmit_pos, bcnt, CSR_BSWP(s));
|
||||
- s->xmit_pos += bcnt;
|
||||
+ goto txdone;
|
||||
+ }
|
||||
#ifdef PCNET_DEBUG
|
||||
- printf("pcnet_transmit size=%d\n", s->xmit_pos);
|
||||
+ printf("pcnet_transmit size=%d\n", s->xmit_pos);
|
||||
#endif
|
||||
- if (CSR_LOOP(s)) {
|
||||
- if (BCR_SWSTYLE(s) == 1)
|
||||
- add_crc = !GET_FIELD(tmd.status, TMDS, NOFCS);
|
||||
- s->looptest = add_crc ? PCNET_LOOPTEST_CRC : PCNET_LOOPTEST_NOCRC;
|
||||
- pcnet_receive(s, s->buffer, s->xmit_pos);
|
||||
- s->looptest = 0;
|
||||
- } else
|
||||
- if (s->vc)
|
||||
- qemu_send_packet(s->vc, s->buffer, s->xmit_pos);
|
||||
-
|
||||
- s->csr[0] &= ~0x0008; /* clear TDMD */
|
||||
- s->csr[4] |= 0x0004; /* set TXSTRT */
|
||||
- s->xmit_pos = -1;
|
||||
+ if (CSR_LOOP(s)) {
|
||||
+ if (BCR_SWSTYLE(s) == 1)
|
||||
+ add_crc = !GET_FIELD(tmd.status, TMDS, NOFCS);
|
||||
+ s->looptest = add_crc ? PCNET_LOOPTEST_CRC : PCNET_LOOPTEST_NOCRC;
|
||||
+ pcnet_receive(s, s->buffer, s->xmit_pos);
|
||||
+ s->looptest = 0;
|
||||
+ } else {
|
||||
+ if (s->vc) {
|
||||
+ qemu_send_packet(s->vc, s->buffer, s->xmit_pos);
|
||||
+ }
|
||||
}
|
||||
|
||||
+ s->csr[0] &= ~0x0008; /* clear TDMD */
|
||||
+ s->csr[4] |= 0x0004; /* set TXSTRT */
|
||||
+ s->xmit_pos = -1;
|
||||
+
|
||||
+ txdone:
|
||||
SET_FIELD(&tmd.status, TMDS, OWN, 0);
|
||||
TMDSTORE(&tmd, PHYSADDR(s,CSR_CXDA(s)));
|
||||
if (!CSR_TOKINTD(s) || (CSR_LTINTEN(s) && GET_FIELD(tmd.status, TMDS, LTINT)))
|
||||
From 2630672ab22255de252f877709851c0557a1c647 Mon Sep 17 00:00:00 2001
|
||||
From: Petr Matousek <pmatouse@redhat.com>
|
||||
Date: Sun, 24 May 2015 10:53:44 +0200
|
||||
Subject: [PATCH] pcnet: force the buffer access to be in bounds during tx
|
||||
|
||||
4096 is the maximum length per TMD and it is also currently the size of
|
||||
the relay buffer pcnet driver uses for sending the packet data to QEMU
|
||||
for further processing. With packet spanning multiple TMDs it can
|
||||
happen that the overall packet size will be bigger than sizeof(buffer),
|
||||
which results in memory corruption.
|
||||
|
||||
Fix this by only allowing to queue maximum sizeof(buffer) bytes.
|
||||
|
||||
This is CVE-2015-3209.
|
||||
|
||||
Signed-off-by: Petr Matousek <pmatouse@redhat.com>
|
||||
Reported-by: Matt Tait <matttait@google.com>
|
||||
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
|
||||
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
|
||||
---
|
||||
hw/pcnet.c | 8 ++++++++
|
||||
1 file changed, 8 insertions(+)
|
||||
|
||||
diff --git a/hw/pcnet.c b/hw/pcnet.c
|
||||
index bdfd38f..6d32e4c 100644
|
||||
--- qemu-xen-traditional/hw/pcnet.c.orig
|
||||
+++ qemu-xen-traditional/hw/pcnet.c
|
||||
@@ -1241,6 +1241,14 @@ static void pcnet_transmit(PCNetState *s)
|
||||
}
|
||||
|
||||
bcnt = 4096 - GET_FIELD(tmd.length, TMDL, BCNT);
|
||||
+
|
||||
+ /* if multi-tmd packet outsizes s->buffer then skip it silently.
|
||||
+ Note: this is not what real hw does */
|
||||
+ if (s->xmit_pos + bcnt > sizeof(s->buffer)) {
|
||||
+ s->xmit_pos = -1;
|
||||
+ goto txdone;
|
||||
+ }
|
||||
+
|
||||
s->phys_mem_read(s->dma_opaque, PHYSADDR(s, tmd.tbadr),
|
||||
s->buffer + s->xmit_pos, bcnt, CSR_BSWP(s));
|
||||
s->xmit_pos += bcnt;
|
||||
--
|
||||
2.1.0
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
$NetBSD: patch-libxl_Makefile,v 1.1 2015/01/20 16:42:13 bouyer Exp $
|
||||
$NetBSD: patch-libxl_Makefile,v 1.2 2015/06/23 17:45:33 bouyer Exp $
|
||||
|
||||
--- libxl/Makefile.orig 2015-01-19 21:18:26.000000000 +0100
|
||||
+++ libxl/Makefile 2015-01-19 21:18:49.000000000 +0100
|
||||
--- libxl/Makefile.orig 2015-06-22 15:41:35.000000000 +0200
|
||||
+++ libxl/Makefile 2015-06-23 16:51:38.000000000 +0200
|
||||
@@ -253,7 +253,7 @@
|
||||
$(INSTALL_DIR) $(DESTDIR)$(SBINDIR)
|
||||
$(INSTALL_DIR) $(DESTDIR)$(LIBDIR)
|
||||
@@ -14,7 +14,7 @@ $NetBSD: patch-libxl_Makefile,v 1.1 2015/01/20 16:42:13 bouyer Exp $
|
||||
@@ -267,7 +267,7 @@
|
||||
$(SYMLINK_SHLIB) libxlutil.so.$(XLUMAJOR) $(DESTDIR)$(LIBDIR)/libxlutil.so
|
||||
$(INSTALL_DATA) libxlutil.a $(DESTDIR)$(LIBDIR)
|
||||
$(INSTALL_DATA) libxl.h libxl_event.h libxl_json.h _libxl_types.h _libxl_types_json.h _libxl_list.h libxl_utils.h libxl_uuid.h $(DESTDIR)$(INCLUDEDIR)
|
||||
$(INSTALL_DATA) libxl.h libxl_event.h libxl_json.h _libxl_types.h _libxl_types_json.h _libxl_list.h libxl_utils.h libxl_uuid.h libxlutil.h $(DESTDIR)$(INCLUDEDIR)
|
||||
- $(INSTALL_DATA) bash-completion $(DESTDIR)$(BASH_COMPLETION_DIR)/xl.sh
|
||||
+ $(INSTALL_DATA) bash-completion $(DESTDIR)$(XEN_EXAMPLES_DIR)/xl.sh
|
||||
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
$NetBSD: patch-qemu-xen-traditional_hw_ide.c,v 1.1 2015/01/20 16:42:13 bouyer Exp $
|
||||
$NetBSD: patch-qemu-xen-traditional_hw_ide.c,v 1.2 2015/06/11 17:43:58 bouyer Exp $
|
||||
|
||||
--- qemu-xen-traditional/hw/ide.c.orig 2014-10-06 17:50:24.000000000 +0200
|
||||
+++ qemu-xen-traditional/hw/ide.c 2015-01-19 13:16:38.000000000 +0100
|
||||
@@ -761,6 +761,7 @@
|
||||
put_le16(p + 61, s->nb_sectors >> 16);
|
||||
--- qemu-xen-traditional/hw/ide.c.orig 2014-01-09 13:44:42.000000000 +0100
|
||||
+++ qemu-xen-traditional/hw/ide.c 2015-06-11 16:15:49.000000000 +0200
|
||||
@@ -757,10 +757,15 @@
|
||||
put_le16(p + 58, oldsize >> 16);
|
||||
if (s->mult_sectors)
|
||||
put_le16(p + 59, 0x100 | s->mult_sectors);
|
||||
- put_le16(p + 60, s->nb_sectors);
|
||||
- put_le16(p + 61, s->nb_sectors >> 16);
|
||||
+ if (s->nb_sectors > 0x10000000)
|
||||
+ oldsize = 0x10000000; /* report only 128GB */
|
||||
+ else
|
||||
+ oldsize = s->nb_sectors;
|
||||
+ put_le16(p + 60, oldsize);
|
||||
+ put_le16(p + 61, oldsize >> 16);
|
||||
put_le16(p + 62, 0x07); /* single word dma0-2 supported */
|
||||
put_le16(p + 63, 0x07); /* mdma0-2 supported */
|
||||
+ put_le16(p + 64, 0x03); /* pio3-4 supported */
|
||||
put_le16(p + 65, 120);
|
||||
put_le16(p + 66, 120);
|
||||
put_le16(p + 67, 120);
|
||||
@@ -812,13 +813,12 @@
|
||||
@@ -812,13 +817,12 @@
|
||||
put_le16(p + 53, 7); /* words 64-70, 54-58, 88 valid */
|
||||
put_le16(p + 62, 7); /* single word dma0-2 supported */
|
||||
put_le16(p + 63, 7); /* mdma0-2 supported */
|
||||
|
||||
Reference in New Issue
Block a user