summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorPeter Marko <peter.marko@siemens.com>2025-10-27 20:13:25 +0100
committerRichard Purdie <richard.purdie@linuxfoundation.org>2025-10-30 11:06:28 +0000
commit941c3ac5a80509c0b7d6cca4f402fd12d8d5806c (patch)
tree5a0f283fee4d51da58d78434f6f955bd3ae519c2 /meta
parent2fbf318ed7524212224e8d62a959443b83419039 (diff)
downloadpoky-941c3ac5a80509c0b7d6cca4f402fd12d8d5806c.tar.gz
qemu: upgrade 10.0.2 -> 10.0.6
Handles CVE-2024-8354. Drop patch included in (backported to) this release. Reference: * https://security-tracker.debian.org/tracker/CVE-2024-8354 (From OE-Core rev: f9d2e0155df2fe799e5edd0b52097ee284930ba5) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-devtools/qemu/qemu-native_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu-native_10.0.2.bb)0
-rw-r--r--meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb)0
-rw-r--r--meta/recipes-devtools/qemu/qemu.inc4
-rw-r--r--meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch85
-rw-r--r--meta/recipes-devtools/qemu/qemu_10.0.6.bb (renamed from meta/recipes-devtools/qemu/qemu_10.0.2.bb)0
5 files changed, 2 insertions, 87 deletions
diff --git a/meta/recipes-devtools/qemu/qemu-native_10.0.2.bb b/meta/recipes-devtools/qemu/qemu-native_10.0.6.bb
index 26fa84c180..26fa84c180 100644
--- a/meta/recipes-devtools/qemu/qemu-native_10.0.2.bb
+++ b/meta/recipes-devtools/qemu/qemu-native_10.0.6.bb
diff --git a/meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb b/meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb
index 22462e2499..22462e2499 100644
--- a/meta/recipes-devtools/qemu/qemu-system-native_10.0.2.bb
+++ b/meta/recipes-devtools/qemu/qemu-system-native_10.0.6.bb
diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc
index 2ee76e9a7c..3ed5dcc671 100644
--- a/meta/recipes-devtools/qemu/qemu.inc
+++ b/meta/recipes-devtools/qemu/qemu.inc
@@ -31,7 +31,6 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \
31 file://0008-Define-MAP_SYNC-and-MAP_SHARED_VALIDATE-on-needed-li.patch \ 31 file://0008-Define-MAP_SYNC-and-MAP_SHARED_VALIDATE-on-needed-li.patch \
32 file://0010-configure-lookup-meson-exutable-from-PATH.patch \ 32 file://0010-configure-lookup-meson-exutable-from-PATH.patch \
33 file://0011-qemu-Ensure-pip-and-the-python-venv-aren-t-used-for-.patch \ 33 file://0011-qemu-Ensure-pip-and-the-python-venv-aren-t-used-for-.patch \
34 file://0012-Remove-deprecated-get_event_loop-calls.patch \
35 file://qemu-guest-agent.init \ 34 file://qemu-guest-agent.init \
36 file://qemu-guest-agent.udev \ 35 file://qemu-guest-agent.udev \
37 " 36 "
@@ -39,7 +38,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \
39UPSTREAM_CHECK_URI = "https://www.qemu.org" 38UPSTREAM_CHECK_URI = "https://www.qemu.org"
40UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar" 39UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar"
41 40
42SRC_URI[sha256sum] = "ef786f2398cb5184600f69aef4d5d691efd44576a3cff4126d38d4c6fec87759" 41SRC_URI[sha256sum] = "c7c40c4b166871e775804e97fce4da65665d1cc93a5c6c9e2ede9d9ee992e7a0"
43 42
44CVE_STATUS[CVE-2007-0998] = "not-applicable-config: The VNC server can expose host files uder some circumstances. We don't enable it by default." 43CVE_STATUS[CVE-2007-0998] = "not-applicable-config: The VNC server can expose host files uder some circumstances. We don't enable it by default."
45 44
@@ -51,6 +50,7 @@ CVE_STATUS[CVE-2023-2680] = "not-applicable-platform: RHEL specific issue."
51 50
52# NVD DB has this CVE as version-less (with "-") 51# NVD DB has this CVE as version-less (with "-")
53CVE_STATUS[CVE-2024-6505] = "fixed-version: this CVE is fixed since 9.1.0" 52CVE_STATUS[CVE-2024-6505] = "fixed-version: this CVE is fixed since 9.1.0"
53CVE_STATUS[CVE-2024-8354] = "fixed-version: this CVE is fixed since 10.0.5"
54 54
55CVE_STATUS[CVE-2023-1386] = "disputed: not an issue as per https://bugzilla.redhat.com/show_bug.cgi?id=2223985" 55CVE_STATUS[CVE-2023-1386] = "disputed: not an issue as per https://bugzilla.redhat.com/show_bug.cgi?id=2223985"
56 56
diff --git a/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch b/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch
deleted file mode 100644
index 64816fe7d9..0000000000
--- a/meta/recipes-devtools/qemu/qemu/0012-Remove-deprecated-get_event_loop-calls.patch
+++ /dev/null
@@ -1,85 +0,0 @@
1From 5240406747fd43886618ae8194153e6fc957a82a Mon Sep 17 00:00:00 2001
2From: John Snow <jsnow@redhat.com>
3Date: Tue, 13 Aug 2024 09:35:30 -0400
4Subject: [PATCH] Remove deprecated get_event_loop calls
5
6This method was deprecated in 3.12 because it ordinarily should not be
7used from coroutines; if there is not a currently running event loop,
8this automatically creates a new event loop - which is usually not what
9you want from code that would ever run in the bottom half.
10
11In our case, we do want this behavior in two places:
12
13(1) The synchronous shim, for convenience: this allows fully sync
14programs to use QEMUMonitorProtocol() without needing to set up an event
15loop beforehand. This is intentional to fully box in the async
16complexities into the legacy sync shim.
17
18(2) The qmp_tui shell; instead of relying on asyncio.run to create and
19run an asyncio program, we need to be able to pass the current asyncio
20loop to urwid setup functions. For convenience, again, we create one if
21one is not present to simplify the creation of the TUI appliance.
22
23The remaining user of get_event_loop() was in fact one of the erroneous
24users that should not have been using this function: if there's no
25running event loop inside of a coroutine, you're in big trouble :)
26
27Upstream-Status: Backport [https://gitlab.com/qemu-project/python-qemu-qmp/-/merge_requests/33]
28Signed-off-by: John Snow <jsnow@redhat.com>
29---
30 python/qemu/qmp/legacy.py | 9 ++++++++-
31 python/qemu/qmp/qmp_tui.py | 7 ++++++-
32 python/tests/protocol.py | 2 +-
33 3 files changed, 15 insertions(+), 3 deletions(-)
34
35diff --git a/python/qemu/qmp/legacy.py b/python/qemu/qmp/legacy.py
36index 22a2b56..ea9b803 100644
37--- a/python/qemu/qmp/legacy.py
38+++ b/python/qemu/qmp/legacy.py
39@@ -86,7 +86,14 @@ def __init__(self,
40 "server argument should be False when passing a socket")
41
42 self._qmp = QMPClient(nickname)
43- self._aloop = asyncio.get_event_loop()
44+
45+ try:
46+ self._aloop = asyncio.get_running_loop()
47+ except RuntimeError:
48+ # No running loop; since this is a sync shim likely to be
49+ # used in fully sync programs, create one if neccessary.
50+ self._aloop = asyncio.get_event_loop_policy().get_event_loop()
51+
52 self._address = address
53 self._timeout: Optional[float] = None
54
55diff --git a/python/qemu/qmp/qmp_tui.py b/python/qemu/qmp/qmp_tui.py
56index 2d9ebbd..d11b9fc 100644
57--- a/python/qemu/qmp/qmp_tui.py
58+++ b/python/qemu/qmp/qmp_tui.py
59@@ -377,7 +377,12 @@ def run(self, debug: bool = False) -> None:
60 screen = urwid.raw_display.Screen()
61 screen.set_terminal_properties(256)
62
63- self.aloop = asyncio.get_event_loop()
64+ try:
65+ self.aloop = asyncio.get_running_loop()
66+ except RuntimeError:
67+ # No running asyncio event loop. Create one if necessary.
68+ self.aloop = asyncio.get_event_loop_policy().get_event_loop()
69+
70 self.aloop.set_debug(debug)
71
72 # Gracefully handle SIGTERM and SIGINT signals
73diff --git a/python/tests/protocol.py b/python/tests/protocol.py
74index 56c4d44..8dcef57 100644
75--- a/python/tests/protocol.py
76+++ b/python/tests/protocol.py
77@@ -228,7 +228,7 @@ def async_test(async_test_method):
78 Decorator; adds SetUp and TearDown to async tests.
79 """
80 async def _wrapper(self, *args, **kwargs):
81- loop = asyncio.get_event_loop()
82+ loop = asyncio.get_running_loop()
83 loop.set_debug(True)
84
85 await self._asyncSetUp()
diff --git a/meta/recipes-devtools/qemu/qemu_10.0.2.bb b/meta/recipes-devtools/qemu/qemu_10.0.6.bb
index 5d544d8d13..5d544d8d13 100644
--- a/meta/recipes-devtools/qemu/qemu_10.0.2.bb
+++ b/meta/recipes-devtools/qemu/qemu_10.0.6.bb