[ubuntu/mantic-proposed] libvirt 9.5.0-2ubuntu1 (Accepted)
Simon Quigley
tsimonq2 at ubuntu.com
Wed Jul 26 17:58:15 UTC 2023
libvirt (9.5.0-2ubuntu1) mantic; urgency=medium
* Merge from Debian Unstable. Remaining changes:
- libvirt-uri.sh, d/rules: Automatically switch default libvirt URI
for users via user profile (xen URI on dom0, qemu:///system otherwise)
- Disable libssh2 support (universe dependency)
- d/control: add libzfslinux-dev to build-deps
- d/control: drop libvirt-lxc, vbox and xen drivers to suggest
- debian/patches/ubuntu/ovmf_paths.patch: adjust paths to secboot.fd UEFI
Secure Boot enabled variants of the OVMF firmware and variable store for
the paths where we ship these files in Ubuntu.
- Set qemu-group to kvm (for compat with older ubuntu)
- Additional apport package-hook
- Autostart default bridged network (As upstream does, but not Debian).
In addition to just enabling it our solution provides:
+ do not autostart if subnet is already taken (e.g. in guests).
+ iterate some alternative subnets before giving up
- d/p/ubuntu/Allow-libvirt-group-to-access-the-socket.patch: This is
the group based access to libvirt functions as it was used in Ubuntu
for quite a long time.
+ d/p/ubuntu/daemon-augeas-fix-expected.patch fix some related tests
due to the group access change.
+ d/libvirt-daemon-system.postinst: add users in sudo to the libvirt
group.
- Update README.Debian with Ubuntu changes
- d/p/ubuntu/ubuntu_machine_type.patch: accept ubuntu types as pci440fx
- fix autopkgtests (LP 1899180)
+ d/t/control, d/t/smoke-qemu-session: fixup smoke-qemu-session by making
vmlinuz available and accessible (Debian bug 848314)
+ d/t/control: fix smoke-qemu-session by ensuring the service will run
installing libvirt-daemon-system
+ d/t/smoke-lxc: fix smoke-lxc by ignoring potential issues on destroy as
long as the following undefine succeeds
+ d/t/smoke-lxc: use systemd instead of sysV to restart the service
+ d/t/control, d/t/smoke-lxc: retry service restart and skip test if
failing; This was flaky on some release/architectures
+ d/t/smoke-lxc: retry check_domain being flaky on arm64
- dnsmasq related enhancements
+ run dnsmasq as libvirt-dnsmasq (LP: 1743718)
+ d/libvirt-daemon-system.postinst: add libvirt-dnsmasq user and group
+ d/libvirt-daemon-system.postrm: remove libvirt-dnsmasq user and group
on purge
+ d/p/ubuntu/dnsmasq-as-priv-user: write dnsmasq config with user
libvirt-dnsmasq and adapt the self tests to expect that config
+ d/libvirt-daemon-system.postinst: fix old libvirt-dnsmasq users group
+ Add dnsmasq configuration to work with system wide dnsmasq-base
- d/p/ubuntu/set-default-machine-to-ubuntu.patch: to select default
machine type correctly with newer qemu/libvirt
- d/p/ubuntu/lp-1861125-ubuntu-models: recognize Ubuntu models for
(LP 1861125) fixups
- d/p/ubuntu/wait-for-qemu-kvm.patch - avoid hangs on startup (LP 1887592)
- d/libvirt-daemon-system.libvirt-guests.default: shut guests down
in parallel
- Apparmor Delta that is Ubuntu specific or yet to be upstreamed
split into logical pieces. File names in debian/patches/ubuntu-aa/:
+ 0020-virt-aa-helper-ubuntu-storage-paths.patch:
apparmor, virt-aa-helper: Allow various storage pools and image
locations
+ 0029-appmor-libvirt-qemu-Add-9p-support.patch: appmor,
libvirt-qemu: Add 9p support
+ 0031-virt-aa-helper-Ask-for-no-deny-rule-for-readonly-dis.patch:
virt-aa-helper: Ask for no deny rule for readonly disk
+ 0032-apparmor-libvirt-qemu-Allow-reading-charm-specific-c.patch:
apparmor, libvirt-qemu: Allow reading charm-specific ceph config
+ 0033-UBUNTU-only-apparmor-for-kvm.powerpc-LP-1680384.patch: allow
commands executed by ubuntu only kvm wrapper on ppc64el
(LP 1686621 LP 1680384 LP 1784023)
+ 0034-apparmor-virt-aa-helper-access-for-snapped-nova.patch:
apparmor, virt-aa-helper: access for snapped nova
+ lp-1815910-allow-vhost-net.patch: avoid apparmor issues
with vhost-net/vhost-vsock/vhost-scsi hotplug (LP: 1815910)
- libvirt should not use user/group tss for swtpm (LP 1948880)
+ d/libvirt-daemon-system.postinst: own swtpm logdir by user swtpm
+ d/p/u/swtpm-by-swtpm-user.patch: change default spawned swtpm processes
to user swtpm and adapt expected self test result changes triggered by
this
+ d/libvirt-daemon-system.postinst: create user/group swtpm if not present
due to swtpm-tools (LP 1951975)
- revert "libvirt-daemon-system: Drop polkit rules in legacy pkla format"
because policykit-1 > 121 isn't yet ready to go to main in lunar.
(LP: #2008830)
- SECURITY UPDATE: denial of service via improper locking
+ debian/patches/CVE-2023-3750.patch: fix returning of locked objects
from virStoragePoolObjListSearch in src/conf/virstorageobj.c.
+ CVE-2023-3750
* Dropped changes [upstream now]:
- SECURITY UPDATE: DoS via memleak in SR-IOV PCI device capabilities
+ debian/patches/CVE-2023-2700.patch: resolve leak in
virPCIVirtualFunctionList cleanup in src/util/virpci.c.
+ CVE-2023-2700
libvirt (9.5.0-2) unstable; urgency=medium
[ Pino Toscano ]
* [2adb625] Enable the glusterfs storage driver only on 64bit architectures
libvirt (9.5.0-1) unstable; urgency=medium
* [cd75481] New upstream version 9.5.0
libvirt (9.4.0-1) experimental; urgency=medium
* [98c5c4c] New upstream version 9.4.0
* [d0f1ab7] patches: Drop debian/Debianize-systemd-service-files.patch
- Changes to the upstream build system make these
Debian-specific modifications no longer necessary
libvirt (9.3.0-2) experimental; urgency=medium
* [4e3ec2a] links: Link /usr/share/doc/* to /usr/share/doc/libvirt0
- The documentation directory for all binary packages (except
for libvirt-doc) is now a symlink to that of libvirt0, which
means that we no longer install 20+ copies of the same files
libvirt (9.3.0-1) experimental; urgency=medium
* [45efa38] New upstream version 9.3.0
- Closes: #1024504
libvirt (9.2.0-2) experimental; urgency=medium
[ Andrea Bolognani ]
* [4d3b6ff] debconf: Add Spanish translation
- Thanks to Jonathan Bustillos (Closes: #986773)
* [5dbd337] debconf: Add Italian translation
- Thanks to Ceppo (Closes: #1019161)
* [23c7d71] debconf: Add Romanian translation
- Thanks to Remus-Gabriel Chelu (Closes: #1032335)
* [faef0ca] patches: Drop forward/Skip-vircgrouptest.patch
- Should no longer be needed
[ Pino Toscano ]
* [351123e] Limit architectures with RBD support
- No longer attempt to build the RBD storage driver on Linux
architectures where Ceph itself is not built (e.g. ppc64)
* [689bbe6] control: switch libc6-dev B-D to libc-dev
- Should make libvirt buildable on architectures that don't
have libc6-dev (e.g. ia64)
libvirt (9.2.0-1) experimental; urgency=medium
* [62fdd34] New upstream version 9.2.0
libvirt (9.1.0-1) experimental; urgency=medium
* [92a1704] New upstream version 9.1.0
* [7c31663] patches: Re-enable passt support
* [85c31f2] patches: Drop backports
* [1268425] rules: Add missing dependencies for libvirt-clients-qemu
Date: Wed, 26 Jul 2023 12:52:15 -0500
Changed-By: Simon Quigley <tsimonq2 at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/libvirt/9.5.0-2ubuntu1
-------------- next part --------------
Format: 1.8
Date: Wed, 26 Jul 2023 12:52:15 -0500
Source: libvirt
Built-For-Profiles: noudeb
Architecture: source
Version: 9.5.0-2ubuntu1
Distribution: mantic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Simon Quigley <tsimonq2 at ubuntu.com>
Closes: 986773 1019161 1024504 1032335
Launchpad-Bugs-Fixed: 2008830
Changes:
libvirt (9.5.0-2ubuntu1) mantic; urgency=medium
.
* Merge from Debian Unstable. Remaining changes:
- libvirt-uri.sh, d/rules: Automatically switch default libvirt URI
for users via user profile (xen URI on dom0, qemu:///system otherwise)
- Disable libssh2 support (universe dependency)
- d/control: add libzfslinux-dev to build-deps
- d/control: drop libvirt-lxc, vbox and xen drivers to suggest
- debian/patches/ubuntu/ovmf_paths.patch: adjust paths to secboot.fd UEFI
Secure Boot enabled variants of the OVMF firmware and variable store for
the paths where we ship these files in Ubuntu.
- Set qemu-group to kvm (for compat with older ubuntu)
- Additional apport package-hook
- Autostart default bridged network (As upstream does, but not Debian).
In addition to just enabling it our solution provides:
+ do not autostart if subnet is already taken (e.g. in guests).
+ iterate some alternative subnets before giving up
- d/p/ubuntu/Allow-libvirt-group-to-access-the-socket.patch: This is
the group based access to libvirt functions as it was used in Ubuntu
for quite a long time.
+ d/p/ubuntu/daemon-augeas-fix-expected.patch fix some related tests
due to the group access change.
+ d/libvirt-daemon-system.postinst: add users in sudo to the libvirt
group.
- Update README.Debian with Ubuntu changes
- d/p/ubuntu/ubuntu_machine_type.patch: accept ubuntu types as pci440fx
- fix autopkgtests (LP 1899180)
+ d/t/control, d/t/smoke-qemu-session: fixup smoke-qemu-session by making
vmlinuz available and accessible (Debian bug 848314)
+ d/t/control: fix smoke-qemu-session by ensuring the service will run
installing libvirt-daemon-system
+ d/t/smoke-lxc: fix smoke-lxc by ignoring potential issues on destroy as
long as the following undefine succeeds
+ d/t/smoke-lxc: use systemd instead of sysV to restart the service
+ d/t/control, d/t/smoke-lxc: retry service restart and skip test if
failing; This was flaky on some release/architectures
+ d/t/smoke-lxc: retry check_domain being flaky on arm64
- dnsmasq related enhancements
+ run dnsmasq as libvirt-dnsmasq (LP: 1743718)
+ d/libvirt-daemon-system.postinst: add libvirt-dnsmasq user and group
+ d/libvirt-daemon-system.postrm: remove libvirt-dnsmasq user and group
on purge
+ d/p/ubuntu/dnsmasq-as-priv-user: write dnsmasq config with user
libvirt-dnsmasq and adapt the self tests to expect that config
+ d/libvirt-daemon-system.postinst: fix old libvirt-dnsmasq users group
+ Add dnsmasq configuration to work with system wide dnsmasq-base
- d/p/ubuntu/set-default-machine-to-ubuntu.patch: to select default
machine type correctly with newer qemu/libvirt
- d/p/ubuntu/lp-1861125-ubuntu-models: recognize Ubuntu models for
(LP 1861125) fixups
- d/p/ubuntu/wait-for-qemu-kvm.patch - avoid hangs on startup (LP 1887592)
- d/libvirt-daemon-system.libvirt-guests.default: shut guests down
in parallel
- Apparmor Delta that is Ubuntu specific or yet to be upstreamed
split into logical pieces. File names in debian/patches/ubuntu-aa/:
+ 0020-virt-aa-helper-ubuntu-storage-paths.patch:
apparmor, virt-aa-helper: Allow various storage pools and image
locations
+ 0029-appmor-libvirt-qemu-Add-9p-support.patch: appmor,
libvirt-qemu: Add 9p support
+ 0031-virt-aa-helper-Ask-for-no-deny-rule-for-readonly-dis.patch:
virt-aa-helper: Ask for no deny rule for readonly disk
+ 0032-apparmor-libvirt-qemu-Allow-reading-charm-specific-c.patch:
apparmor, libvirt-qemu: Allow reading charm-specific ceph config
+ 0033-UBUNTU-only-apparmor-for-kvm.powerpc-LP-1680384.patch: allow
commands executed by ubuntu only kvm wrapper on ppc64el
(LP 1686621 LP 1680384 LP 1784023)
+ 0034-apparmor-virt-aa-helper-access-for-snapped-nova.patch:
apparmor, virt-aa-helper: access for snapped nova
+ lp-1815910-allow-vhost-net.patch: avoid apparmor issues
with vhost-net/vhost-vsock/vhost-scsi hotplug (LP: 1815910)
- libvirt should not use user/group tss for swtpm (LP 1948880)
+ d/libvirt-daemon-system.postinst: own swtpm logdir by user swtpm
+ d/p/u/swtpm-by-swtpm-user.patch: change default spawned swtpm processes
to user swtpm and adapt expected self test result changes triggered by
this
+ d/libvirt-daemon-system.postinst: create user/group swtpm if not present
due to swtpm-tools (LP 1951975)
- revert "libvirt-daemon-system: Drop polkit rules in legacy pkla format"
because policykit-1 > 121 isn't yet ready to go to main in lunar.
(LP: #2008830)
- SECURITY UPDATE: denial of service via improper locking
+ debian/patches/CVE-2023-3750.patch: fix returning of locked objects
from virStoragePoolObjListSearch in src/conf/virstorageobj.c.
+ CVE-2023-3750
* Dropped changes [upstream now]:
- SECURITY UPDATE: DoS via memleak in SR-IOV PCI device capabilities
+ debian/patches/CVE-2023-2700.patch: resolve leak in
virPCIVirtualFunctionList cleanup in src/util/virpci.c.
+ CVE-2023-2700
.
libvirt (9.5.0-2) unstable; urgency=medium
.
[ Pino Toscano ]
* [2adb625] Enable the glusterfs storage driver only on 64bit architectures
.
libvirt (9.5.0-1) unstable; urgency=medium
.
* [cd75481] New upstream version 9.5.0
.
libvirt (9.4.0-1) experimental; urgency=medium
.
* [98c5c4c] New upstream version 9.4.0
* [d0f1ab7] patches: Drop debian/Debianize-systemd-service-files.patch
- Changes to the upstream build system make these
Debian-specific modifications no longer necessary
.
libvirt (9.3.0-2) experimental; urgency=medium
.
* [4e3ec2a] links: Link /usr/share/doc/* to /usr/share/doc/libvirt0
- The documentation directory for all binary packages (except
for libvirt-doc) is now a symlink to that of libvirt0, which
means that we no longer install 20+ copies of the same files
.
libvirt (9.3.0-1) experimental; urgency=medium
.
* [45efa38] New upstream version 9.3.0
- Closes: #1024504
.
libvirt (9.2.0-2) experimental; urgency=medium
.
[ Andrea Bolognani ]
* [4d3b6ff] debconf: Add Spanish translation
- Thanks to Jonathan Bustillos (Closes: #986773)
* [5dbd337] debconf: Add Italian translation
- Thanks to Ceppo (Closes: #1019161)
* [23c7d71] debconf: Add Romanian translation
- Thanks to Remus-Gabriel Chelu (Closes: #1032335)
* [faef0ca] patches: Drop forward/Skip-vircgrouptest.patch
- Should no longer be needed
.
[ Pino Toscano ]
* [351123e] Limit architectures with RBD support
- No longer attempt to build the RBD storage driver on Linux
architectures where Ceph itself is not built (e.g. ppc64)
* [689bbe6] control: switch libc6-dev B-D to libc-dev
- Should make libvirt buildable on architectures that don't
have libc6-dev (e.g. ia64)
.
libvirt (9.2.0-1) experimental; urgency=medium
.
* [62fdd34] New upstream version 9.2.0
.
libvirt (9.1.0-1) experimental; urgency=medium
.
* [92a1704] New upstream version 9.1.0
* [7c31663] patches: Re-enable passt support
* [85c31f2] patches: Drop backports
* [1268425] rules: Add missing dependencies for libvirt-clients-qemu
Checksums-Sha1:
67c793de1f001bfb7c279bcf793a0f97c9104eb5 6032 libvirt_9.5.0-2ubuntu1.dsc
472f6871651d8d3b41b2a2602adfcdb18629049d 9261176 libvirt_9.5.0.orig.tar.xz
0294bea07a713950d38e96f4fd9d7817aaf02f8e 833 libvirt_9.5.0.orig.tar.xz.asc
cd5ea661aa4f04019fbe283bbe3b55a9b2e9f342 150268 libvirt_9.5.0-2ubuntu1.debian.tar.xz
82385d3364daf16031dd566cfd8ac34fbca059af 10424 libvirt_9.5.0-2ubuntu1_source.buildinfo
Checksums-Sha256:
9179bed1aacc37dfd07a44c18b138f95a24082d05b2e5504de69678d97354600 6032 libvirt_9.5.0-2ubuntu1.dsc
df5ea2272c4d1ce1889892d88292506616c1e10ebe8ecdeac7928f2ebdc3044a 9261176 libvirt_9.5.0.orig.tar.xz
be81019a6c477210fdd17ffe1275645872463d386d0a8815135f53e711587239 833 libvirt_9.5.0.orig.tar.xz.asc
082f30830875f2376b6849457aeb74727332e533772cd866e622c24ad5b51068 150268 libvirt_9.5.0-2ubuntu1.debian.tar.xz
613f1c3177633dde1b889ef94eb28ee70a5279870c871cccc3265aae0493df8b 10424 libvirt_9.5.0-2ubuntu1_source.buildinfo
Files:
09cfa88551d4b13f177475939d2b7ab8 6032 libs optional libvirt_9.5.0-2ubuntu1.dsc
7b153b9b3f659e951dc183a606e571b5 9261176 libs optional libvirt_9.5.0.orig.tar.xz
ac63392ae197481dfd289e829ffe3ff8 833 libs optional libvirt_9.5.0.orig.tar.xz.asc
2a8503d0e5794b3ff5bca170faf2487a 150268 libs optional libvirt_9.5.0-2ubuntu1.debian.tar.xz
1ae95668cb63a94ed5323bfb32f9fbcd 10424 libs optional libvirt_9.5.0-2ubuntu1_source.buildinfo
Original-Maintainer: Debian Libvirt Maintainers <pkg-libvirt-maintainers at lists.alioth.debian.org>
More information about the mantic-changes
mailing list