diff options
| author | Peter Marko <peter.marko@siemens.com> | 2025-10-27 20:13:25 +0100 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2025-10-30 11:06:28 +0000 |
| commit | 941c3ac5a80509c0b7d6cca4f402fd12d8d5806c (patch) | |
| tree | 5a0f283fee4d51da58d78434f6f955bd3ae519c2 /meta | |
| parent | 2fbf318ed7524212224e8d62a959443b83419039 (diff) | |
| download | poky-941c3ac5a80509c0b7d6cca4f402fd12d8d5806c.tar.gz | |
qemu: upgrade 10.0.2 -> 10.0.6
Handles CVE-2024-8354.
Drop patch included in (backported to) this release.
Reference:
* https://security-tracker.debian.org/tracker/CVE-2024-8354
(From OE-Core rev: f9d2e0155df2fe799e5edd0b52097ee284930ba5)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta')
| -rw-r--r-- | meta/recipes-devtools/qemu/qemu-native_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu-native_10.0.2.bb) | 0 | ||||
| -rw-r--r-- | meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb) | 0 | ||||
| -rw-r--r-- | meta/recipes-devtools/qemu/qemu.inc | 4 | ||||
| -rw-r--r-- | meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch | 85 | ||||
| -rw-r--r-- | meta/recipes-devtools/qemu/qemu_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu_10.0.2.bb) | 0 |
5 files changed, 2 insertions, 87 deletions
diff --git a/meta/recipes-devtools/qemu/qemu-native_10.0.2.bb b/meta/recipes-devtools/qemu/qemu-native_10.0.6.bb index 26fa84c180..26fa84c180 100644 --- a/meta/recipes-devtools/qemu/qemu-native_10.0.2.bb +++ b/meta/recipes-devtools/qemu/qemu-native_10.0.6.bb | |||
diff --git a/meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb b/meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb index 22462e2499..22462e2499 100644 --- a/meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb +++ b/meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb | |||
diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index 2ee76e9a7c..3ed5dcc671 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc | |||
| @@ -31,7 +31,6 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \ | |||
| 31 | file://0008-Define-MAP_SYNC-and-MAP_SHARED_VALIDATE-on-needed-li.patch \ | 31 | file://0008-Define-MAP_SYNC-and-MAP_SHARED_VALIDATE-on-needed-li.patch \ |
| 32 | file://0010-configure-lookup-meson-exutable-from-PATH.patch \ | 32 | file://0010-configure-lookup-meson-exutable-from-PATH.patch \ |
| 33 | file://0011-qemu-Ensure-pip-and-the-python-venv-aren-t-used-for-.patch \ | 33 | file://0011-qemu-Ensure-pip-and-the-python-venv-aren-t-used-for-.patch \ |
| 34 | file://0012-Remove-deprecated-get_event_loop-calls.patch \ | ||
| 35 | file://qemu-guest-agent.init \ | 34 | file://qemu-guest-agent.init \ |
| 36 | file://qemu-guest-agent.udev \ | 35 | file://qemu-guest-agent.udev \ |
| 37 | " | 36 | " |
| @@ -39,7 +38,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \ | |||
| 39 | UPSTREAM_CHECK_URI = "https://www.qemu.org" | 38 | UPSTREAM_CHECK_URI = "https://www.qemu.org" |
| 40 | UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar" | 39 | UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar" |
| 41 | 40 | ||
| 42 | SRC_URI[sha256sum] = "ef786f2398cb5184600f69aef4d5d691efd44576a3cff4126d38d4c6fec87759" | 41 | SRC_URI[sha256sum] = "c7c40c4b166871e775804e97fce4da65665d1cc93a5c6c9e2ede9d9ee992e7a0" |
| 43 | 42 | ||
| 44 | CVE_STATUS[CVE-2007-0998] = "not-applicable-config: The VNC server can expose host files uder some circumstances. We don't enable it by default." | 43 | CVE_STATUS[CVE-2007-0998] = "not-applicable-config: The VNC server can expose host files uder some circumstances. We don't enable it by default." |
| 45 | 44 | ||
| @@ -51,6 +50,7 @@ CVE_STATUS[CVE-2023-2680] = "not-applicable-platform: RHEL specific issue." | |||
| 51 | 50 | ||
| 52 | # NVD DB has this CVE as version-less (with "-") | 51 | # NVD DB has this CVE as version-less (with "-") |
| 53 | CVE_STATUS[CVE-2024-6505] = "fixed-version: this CVE is fixed since 9.1.0" | 52 | CVE_STATUS[CVE-2024-6505] = "fixed-version: this CVE is fixed since 9.1.0" |
| 53 | CVE_STATUS[CVE-2024-8354] = "fixed-version: this CVE is fixed since 10.0.5" | ||
| 54 | 54 | ||
| 55 | CVE_STATUS[CVE-2023-1386] = "disputed: not an issue as per https://bugzilla.redhat.com/show_bug.cgi?id=2223985" | 55 | CVE_STATUS[CVE-2023-1386] = "disputed: not an issue as per https://bugzilla.redhat.com/show_bug.cgi?id=2223985" |
| 56 | 56 | ||
diff --git a/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch b/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch deleted file mode 100644 index 64816fe7d9..0000000000 --- a/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch +++ /dev/null | |||
| @@ -1,85 +0,0 @@ | |||
| 1 | From 5240406747fd43886618ae8194153e6fc957a82a Mon Sep 17 00:00:00 2001 | ||
| 2 | From: John Snow <jsnow@redhat.com> | ||
| 3 | Date: Tue, 13 Aug 2024 09:35:30 -0400 | ||
| 4 | Subject: [PATCH] Remove deprecated get_event_loop calls | ||
| 5 | |||
| 6 | This method was deprecated in 3.12 because it ordinarily should not be | ||
| 7 | used from coroutines; if there is not a currently running event loop, | ||
| 8 | this automatically creates a new event loop - which is usually not what | ||
| 9 | you want from code that would ever run in the bottom half. | ||
| 10 | |||
| 11 | In our case, we do want this behavior in two places: | ||
| 12 | |||
| 13 | (1) The synchronous shim, for convenience: this allows fully sync | ||
| 14 | programs to use QEMUMonitorProtocol() without needing to set up an event | ||
| 15 | loop beforehand. This is intentional to fully box in the async | ||
| 16 | complexities into the legacy sync shim. | ||
| 17 | |||
| 18 | (2) The qmp_tui shell; instead of relying on asyncio.run to create and | ||
| 19 | run an asyncio program, we need to be able to pass the current asyncio | ||
| 20 | loop to urwid setup functions. For convenience, again, we create one if | ||
| 21 | one is not present to simplify the creation of the TUI appliance. | ||
| 22 | |||
| 23 | The remaining user of get_event_loop() was in fact one of the erroneous | ||
| 24 | users that should not have been using this function: if there's no | ||
| 25 | running event loop inside of a coroutine, you're in big trouble :) | ||
| 26 | |||
| 27 | Upstream-Status: Backport [https://gitlab.com/qemu-project/python-qemu-qmp/-/merge_requests/33] | ||
| 28 | Signed-off-by: John Snow <jsnow@redhat.com> | ||
| 29 | --- | ||
| 30 | python/qemu/qmp/legacy.py | 9 ++++++++- | ||
| 31 | python/qemu/qmp/qmp_tui.py | 7 ++++++- | ||
| 32 | python/tests/protocol.py | 2 +- | ||
| 33 | 3 files changed, 15 insertions(+), 3 deletions(-) | ||
| 34 | |||
| 35 | diff --git a/python/qemu/qmp/legacy.py b/python/qemu/qmp/legacy.py | ||
| 36 | index 22a2b56..ea9b803 100644 | ||
| 37 | --- a/python/qemu/qmp/legacy.py | ||
| 38 | +++ b/python/qemu/qmp/legacy.py | ||
| 39 | @@ -86,7 +86,14 @@ def __init__(self, | ||
| 40 | "server argument should be False when passing a socket") | ||
| 41 | |||
| 42 | self._qmp = QMPClient(nickname) | ||
| 43 | - self._aloop = asyncio.get_event_loop() | ||
| 44 | + | ||
| 45 | + try: | ||
| 46 | + self._aloop = asyncio.get_running_loop() | ||
| 47 | + except RuntimeError: | ||
| 48 | + # No running loop; since this is a sync shim likely to be | ||
| 49 | + # used in fully sync programs, create one if neccessary. | ||
| 50 | + self._aloop = asyncio.get_event_loop_policy().get_event_loop() | ||
| 51 | + | ||
| 52 | self._address = address | ||
| 53 | self._timeout: Optional[float] = None | ||
| 54 | |||
| 55 | diff --git a/python/qemu/qmp/qmp_tui.py b/python/qemu/qmp/qmp_tui.py | ||
| 56 | index 2d9ebbd..d11b9fc 100644 | ||
| 57 | --- a/python/qemu/qmp/qmp_tui.py | ||
| 58 | +++ b/python/qemu/qmp/qmp_tui.py | ||
| 59 | @@ -377,7 +377,12 @@ def run(self, debug: bool = False) -> None: | ||
| 60 | screen = urwid.raw_display.Screen() | ||
| 61 | screen.set_terminal_properties(256) | ||
| 62 | |||
| 63 | - self.aloop = asyncio.get_event_loop() | ||
| 64 | + try: | ||
| 65 | + self.aloop = asyncio.get_running_loop() | ||
| 66 | + except RuntimeError: | ||
| 67 | + # No running asyncio event loop. Create one if necessary. | ||
| 68 | + self.aloop = asyncio.get_event_loop_policy().get_event_loop() | ||
| 69 | + | ||
| 70 | self.aloop.set_debug(debug) | ||
| 71 | |||
| 72 | # Gracefully handle SIGTERM and SIGINT signals | ||
| 73 | diff --git a/python/tests/protocol.py b/python/tests/protocol.py | ||
| 74 | index 56c4d44..8dcef57 100644 | ||
| 75 | --- a/python/tests/protocol.py | ||
| 76 | +++ b/python/tests/protocol.py | ||
| 77 | @@ -228,7 +228,7 @@ def async_test(async_test_method): | ||
| 78 | Decorator; adds SetUp and TearDown to async tests. | ||
| 79 | """ | ||
| 80 | async def _wrapper(self, *args, **kwargs): | ||
| 81 | - loop = asyncio.get_event_loop() | ||
| 82 | + loop = asyncio.get_running_loop() | ||
| 83 | loop.set_debug(True) | ||
| 84 | |||
| 85 | await self._asyncSetUp() | ||
diff --git a/meta/recipes-devtools/qemu/qemu_10.0.2.bb b/meta/recipes-devtools/qemu/qemu_10.0.6.bb index 5d544d8d13..5d544d8d13 100644 --- a/meta/recipes-devtools/qemu/qemu_10.0.2.bb +++ b/meta/recipes-devtools/qemu/qemu_10.0.6.bb | |||
