[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH for-4.15 6/7] CHANGELOG.md: Various entries, mostly xenstore


  • To: Andrew Cooper <Andrew.Cooper3@xxxxxxxxxx>
  • From: George Dunlap <George.Dunlap@xxxxxxxxxx>
  • Date: Thu, 1 Apr 2021 14:13:52 +0000
  • Accept-language: en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cOZ/xI/emguW5oKlhPWLjfpXpQISZ5k4MxVTlymcgYc=; b=Wk4KbsAzDUhSa+hn9VC/USL3Bqjtjacbn6wsUsxXWeHucLX81c8YTDhz65pQ1ZoOSd+6zP9621qQ59RPhlv4voYpATfLXrWTEx8OrUuw8UiNdQu0nQRG8GczIjC8kSscKJ4VaYeQtQ+ToEFcYx2fWS76cOs9lD5mC35rDFVayXQoArJ+RKZ37YB81mEpoZpJqajYbqm7HVmAIhWwkV1DKoNyiUw0oQZ4FUw30ZcHLCV2pmc65ljWXf1P92tLwzJgk56DHNroMhRswOjS+xhOR2b4MdPetj2HOKZmMrHy1z1hlmZ5C07bPlZ2a9CWn3R7oxOesYzKvl0QDwctHpwehw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Pab5V570b3uVVy8Xwyh+s3KstQBUM2HEM4mcBBjI9ZqtDSI3NgBiIA9eGO7nTW2IkAaSRhGURIONmn1Z23Zg0CuNAX/qtGUfri8sN9sn2xFBD3ADBC1SeASaGGnyw+W1VAL+Mz0YpqxPoMExPGTvmBEWooV5seP2PaPeXreWFRf7FUIjE1o5qXYvuTlFaVnTpehPX09riYnFZDqPdvIOLDfsSCivTP28C//bshMsx2NU+x3hgnJ9VUWLpCe+vI87mqZW+xra3+cVAeFrcujtoa4bF8iLPstjBy7cE+153WMZuj6RnxgzK5YjICPbKI7vEWiNGEz22BZh95d7w+id1A==
  • Authentication-results: esa3.hc3370-68.iphmx.com; dkim=pass (signature verified) header.i=@citrix.onmicrosoft.com
  • Cc: xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Juergen Gross <jgross@xxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Ian Jackson <Ian.Jackson@xxxxxxxxxx>
  • Delivery-date: Thu, 01 Apr 2021 14:13:59 +0000
  • Ironport-hdrordr: A9a23:tIatg6vs00lmrAMUoe0kr8897skCC4cji2hD6mlwRA09T+WxrO rrtOgH1BPylTYaUGwhn9fFA6WbXXbA7/dOj7U5FYyJGC3ronGhIo0n14vtxDX8Bzbzn9Qz6Y 5JSII7MtH5CDFB4frSyAOzH888hPyO9661jenTpk0dMT1CQYsI1XYcNi+wFEpqSA5aQboVfa Dsp/ZvjTymZHgRc4CfDn4KQ+DMq7Tw5e3bSDQBAAMq7xTLsCih76T0HwPd8hAVVT5OxrlKyx mEryXS4KK/v/anjiLNzmO71eUZpPLN6PtmQPaNhM8cNyn2hm+TBbhJdrWesFkO0ZmSwXkwlt 2kmWZDA+1S7DfrcnixsV/R3WDboUsTwlvD7XPdvnf5u8z+Q1sBeol8rKZUaAHQ5UZlnPwU6t Mx40uju5BaDQzNkU3GjrCiPXwL5ymJiEEvnuIJg3tUXZF2Us4qkaUl8F5IC5BFJSrm6ekcYb RTJfvB7/Vbe07yVQG/gkBTwcehVnl2PhCKTllqgL3t7xFqnWt0x0Zd+coHnn1ozuNad7B44Y 3/Q8FVvYALavVTQbN2Be8HT8fyIHfKWwjwPGWbJkmiPL0bOlrWwqSHookd1aWPQtgl3ZEykJ POXBdzrmgpYX/jDsWIwdli7g3NemOgRj7go/suoqRRi/nZfv7GICeDQFchn4+LuPMEGPDWXP 61JdZwD+L8K3DtXaJExRf3VZUXCXR2arxQhv8LH3a15u7bIIzjseLWNNzJIqD2LDoiUmTjRn QZWjz+I9hB81CrVnf0jAO5YQKqRmXPubZLVITK9ekaz4YAcqdWtBIOtFi/7saXbT1O25ZGJX dWEffCqOeWtGO29WHH4yFCIRxGFHtY573mTjdPrQ8OOEXkbKYbt7ykCDhv9UrCAiU6Y9LdEQ ZZqVgy07mwNYasyScrDM/iNHmbgXsVrHeDVIwdhaWH+MfgdvoDf9EbcZ00MT+OOw1+mA5spm sGQhQDXFXjGjTnjrjgkIYZH/jFd953gB6iJMldrX63jzTGmegfAl8gGxK+W8+ehggjAwdOjl pq6qkFnf6rgjC0M1Yyh+w+LXxBYGmaG6h9EQyAfYlY84qbIj1YfCOvv3i6gwt2Unf2/08S71 aRUxG8SLXuOB5hnVx2lozt60h5c22BeVkYUAEKjaRNUULcunhy1ueXYLGUyGX5UCpf/sgULC zFbTwOIgln2tCw01qPlCyfEGg9r69eTdD1HfAtdare1WiqL5DNnaYaH+VM9JIgL9z2tPQXON jvNzO9PXf9A+Mt1xf9nAdUBABk7H0lm+jvwhvr8Syx22M+G+PbJD1dNvsmCsDZ62jvXPCT1p plydozoOurK230LtqL07veYTIGKhTdpweNPqwVgIERuaI5r71oGZbHFTPOyXFcxR07aN7ui1 l2etUz3JnRfot0O8ACcSNQ+VQk0NyJMUswqwTzRuszZ0skgXPXN86AioC45oYHEwmEvk/9KF Of+ypS87PeUyyP2aUTBqgwLW5VAXJMo0hK7aeHbcndGQ+qf+ZM8B6mKXe7aqZaU7XAFrMKrB p2iuv46dO/Zm79wkTXsjR6KK4VrDriTsO2HQ6WGelHt9a9Ik+Bh6O24Mi1yDf7IAHLH3gwlM lAbwgXaM8GlzwpyIsw2SK2Qrbsok0kn0BFiAsX3mLFy8yj+iPDAUpCMQfFmZ1YUjlYL2iQga 3+gJ2l/WW45CIAxILKG0hRdMxfAtQcToD4KCF1NMgb1YTYiJYHk2BEexchD2k1lTD70adnxN 6CqYfvZ9E=
  • Ironport-sdr: hedOiDKEWSy1774H3QXvtOwJ3AtPi3v9m9j4g3Aa4HTdwLVR3cbaiduS7KcI8KHcvho2iKw7SX /cQy3EMBIOZRZyG/oGlmRWjmOZDicKM4t/R+GUIv63ddRCgG9cC78ntj3EkSTSHpyfc7Y5wXvg 3WNdjCXhagvdh0cWaJ0wdr2yOuVek3jGv3qIADTb9gtUrEuC0tIMjkz2hxcP80CD/VxEFhvfjT Y5wY29BgFrza/TXhdX8c+PPqDExVHlllUg6kctlCG8iq/42wcUHL6ynHlOtGLOcuvw0CFUsvMx TXU=
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHXJvxUtSxo6M4mo0iX7TVVNapv+6qfsM2AgAADtYA=
  • Thread-topic: [PATCH for-4.15 6/7] CHANGELOG.md: Various entries, mostly xenstore


> On Apr 1, 2021, at 3:00 PM, Andrew Cooper <andrew.cooper3@xxxxxxxxxx> wrote:
> 
> On 01/04/2021 14:38, George Dunlap wrote:
>> ...grouped by submitters / maintainers
>> 
>> Signed-off-by: George Dunlap <george.dunlap@xxxxxxxxxx>
>> ---
>> CC: Juergen Gross <jgross@xxxxxxxx>
>> CC: Jan Beulich <jbeulich@xxxxxxxx>
>> CC: Ian Jackson <ian.jackson@xxxxxxxxxx>
>> ---
>> CHANGELOG.md | 3 +++
>> 1 file changed, 3 insertions(+)
>> 
>> diff --git a/CHANGELOG.md b/CHANGELOG.md
>> index 2f26cd5c87..9c272a0113 100644
>> --- a/CHANGELOG.md
>> +++ b/CHANGELOG.md
>> @@ -28,8 +28,11 @@ The format is based on [Keep a 
>> Changelog](https://keepachangelog.com/en/1.0.0/)
>>  - Factored out HVM-specific shadow code, improving code clarity and 
>> reducing the size of PV-only hypervisor builds
>>  - Added XEN_SCRIPT_DIR configuration option to specify location for Xen 
>> scripts, rather than hard-coding /etc/xen/scripts
>>  - xennet: Documented a way for the backend (or toolstack) to specify MTU to 
>> the frontend
>> + - Fix permissions for watches on @introduceDomain and @releaseDomain: By 
>> default, only privileged domains can set watches; but specific domains can 
>> be given permission in order to allow disaggregation.
> 
> This is XSA-115, and isn't something new in 4.15 vs 4.14.  (I think?)

XSA-115 went public during the 4.15 development window.

So on the one hand, it’s certainly effort that happened during the window, 
which it would be good to highlight.   On the other hand, it was backported to 
all security supported trees (?), so it’s not something you need to update to 
4.15 to get.

Honestly not sure the best thing to suggest here.

> 
>> + - xenstore can now be live-updated on a running system.
> 
> This needs to be very clear that it is tech preview.  It does not
> currently work cleanly if a malicious VM deliberately holds a
> transaction open.

OK, I’ll add (tech preview) at the end.

Thanks,
 -George

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.