[Oraclevm-errata] OVMSA-2017-0142 Oracle VM 3.4 xen security update

Errata Announcements for Oracle VM oraclevm-errata at oss.oracle.com
Tue Aug 29 08:00:19 PDT 2017


Oracle VM Security Advisory OVMSA-2017-0142

The following updated rpms for Oracle VM 3.4 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
xen-4.4.4-155.el6.x86_64.rpm
xen-tools-4.4.4-155.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/oraclevm/server/3.4/SRPMS-updates/xen-4.4.4-155.el6.src.rpm



Description of changes:

[4.4.4-155.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=a093e86f85280e92c41b1782a409c3029c53c61b
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- grant_table: Set max grant table version to 2 (Boris Ostrovsky) 
[Orabug: 26564064]

[4.4.4-154.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=453e4fd031596351200e96224f89789e29d9bddc
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- gnttab: correct pin status fixup for copy (Jan Beulich)  [Orabug: 
26591253]
- gnttab: split maptrack lock to make it fulfill its purpose again (Jan 
Beulich)  [Orabug: 26564140]  {CVE-2017-12136}
- x86/grant: Disallow misaligned PTEs (Andrew Cooper)  [Orabug: 
26564118]  {CVE-2017-12137}
- grant_table: Default to v1, and disallow transitive grants (Andrew 
Cooper)  [Orabug: 26564064]  {CVE-2017-12135}

[4.4.4-153.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=610401e026e333a31402c4e47107e2d51f40e88e
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86/apic/x2apic: Share IRQ vector between cluster members only when 
cpumask is specified (Boris Ostrovsky)  [Orabug: 26360629]

[4.4.4-152.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=4ff73534ac66685dc3aec163572119979d3bd4c5
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: ignore non-vNUMA VMs in nodeload if vm config has no "cpus" 
(Elena Ufimtseva)  [Orabug: 26498675]
- xend: fix vcpu_to_vnuma mask construction (Elena Ufimtseva)  [Orabug: 
26533429]

[4.4.4-151.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=4fb62266d3b7ebca86cee661e1fbb77ffb9ece38
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- use more fixed strings to build the hypervisor (Olaf Hering) - xen: 
elfloader: increase limit on number of sections in module (Vegard Nossum)

[4.4.4-150.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=cc2b44e080fb2685d2141acee704f7e360366653
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: disable vNUMA on per-guest basis (Elena Ufimtseva)

[4.4.4-149.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=0f91c081f9a8c9c8645151ce6172358644477040
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: add support for asymmetrical manual vNUMA (Elena Ufimtseva) 
[Orabug: 26521752]
- xend: fix vNUMA construction in manual mode (Elena Ufimtseva) 
[Orabug: 26521752]
- xend: make vNUMA vcpus assignment balanced (Elena Ufimtseva)  [Orabug: 
26520165]
- xend: move code into function (Elena Ufimtseva)

[4.4.4-148.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=9b9f328f2102af405153eb336c405255dfd65eee
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Red-tape: Update the repo with CVEs for XSA-[217,218,219,221,222,224] 
(Konrad Rzeszutek Wilk)  [Orabug: 26520525]  {CVE-2017-10920} 
{CVE-2017-10921} {CVE-2017-10922} {CVE-2017-10915} {CVE-2017-10912} 
{CVE-2017-10918} {CVE-2017-10917} {CVE-2017-10913} {CVE-2017-10914}

[4.4.4-147.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=63efdff9b21596d716586c3123db52a66baacaee
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: vNUMA 8 numa node support for low-performance VMs (Elena Ufimtseva)

[4.4.4-146.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=6bcdf6da713b4950da61e612b4e3dda1f4b17ce6
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: hvm guest keeps using original maxmem and memory after xend 
restart (Annie Li)  [Orabug: 26396728]
- xend: change error message when no cpus found for pinning (Elena 
Ufimtseva) - xen: allow to construct vNUMA guests with even number of 
vCPUs. (Elena Ufimtseva)  [Orabug: 26377715] [Orabug: 26377675]
- xend: allow vNUMA VMs with multiple of sockets vcpus (Elena Ufimtseva) 
  [Orabug: 26377715] [Orabug: 26377675]

[4.4.4-145.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=a7bfce28689fe284396d5c4a91b8746398e1e1bb
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- gitignore: add tools/misc/xen-diag to .gitignore (Dongli Zhang) 
[Orabug: 26391286]
- tools: utility to dump guest grant table info (Dongli Zhang)  [Orabug: 
26391286]
- tools/libxc: add interface for GNTTABOP_query_size (Dongli Zhang) 
[Orabug: 26391286]

[4.4.4-144.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=8e9c6a5b7652717317fe7c6f5b7c251f67c4a018
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend/vnuma: Don't try allocating or finding memory for a kdump guest. 
(Konrad Rzeszutek Wilk)  [Orabug: 26354498]
- xend/python: Fix vNUMA: disable memory relocation if ib_pfs or pci are 
present (Konrad Rzeszutek Wilk)  [Orabug: 26413649]

[4.4.4-143.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=69549b08eb9bd3a525c07a97d952673a3d02c76a
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xen: increase default max grant frames and max maptrack frames (Annie Li)

[4.4.4-142.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=4a781c6460724a28668ff2d1e9a800d0cf0fb5ae
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: change the error message if vcpus and 'cpus' dont match (Elena 
Ufimtseva) - xend: fix vNUMA on xm reboot (Elena Ufimtseva)  [Orabug: 
26354498]

[4.4.4-141.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=9dfba034e66bc55a9e03d1921fdbf697f55d7768
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xen: Increase default max grant frames and PIRQs numbers (Annie Li) 
[Orabug: 26338166]

[4.4.4-140.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=4f5e03612105ed392c82bc58a88e0fc59f0b3c3f
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- gnttab: __gnttab_unmap_common_complete() is all-or-nothing (Jan 
Beulich)  [Orabug: 26199373]
- gnttab: correct logic to get page references during map requests 
(George Dunlap)  [Orabug: 26199373]
- gnttab: never create host mapping unless asked to (Jan Beulich) 
[Orabug: 26199373]
- gnttab: Fix handling of dev_bus_addr during unmap (George Dunlap) 
[Orabug: 26199373]
- x86/shadow: Hold references for the duration of emulated writes 
(Andrew Cooper)  [Orabug: 26199131]
- x86/mm: disallow page stealing from HVM domains (Jan Beulich) 
[Orabug: 26199019]
- guest_physmap_remove_page() needs its return value checked (Jan 
Beulich)  [Orabug: 26199335]
- xen/memory: Fix return value handing of guest_remove_page() (Andrew 
Cooper)  [Orabug: 26199335]
- evtchn: avoid NULL derefs (Jan Beulich)  [Orabug: 26199287]
- gnttab: correct maptrack table accesses (Jan Beulich)  [Orabug: 26199098]
- gnttab: Avoid potential double-put of maptrack entry (George Dunlap) 
[Orabug: 26199098]
- gnttab: fix unmap pin accounting race (Jan Beulich)  [Orabug: 26199098]
- IOMMU: handle IOMMU mapping and unmapping failures (Quan Xu)  [Orabug: 
26199098]
- xend: override memory relocation disable (Elena Ufimtseva)  [Orabug: 
26046538]
- vNUMA: disable memory relocation if ib_pfs or pci are present (Elena 
Ufimtseva)  [Orabug: 26046538]
- xend: vNUMA make all memory units in KBytes. (Elena Ufimtseva) 
[Orabug: 26046538]
- xc/python: use common paths to parse vnuma topology (Elena Ufimtseva) 
[Orabug: 26046538]

[4.4.4-139.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=2b1e5d98846bdf4a2df85fa75ad6af70717a2203
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- OVMF: build against specific ovmf.git commit instead of master 
(Zhigang Wang)  [Orabug: 26248846]

[4.4.4-138.el6]
- BUILDINFO: OVMF commit=173bf5c847e3ca8b42c11796ce048d8e2e916ff8
- BUILDINFO: xen commit=74a643c566912da76d71e9a7bde14fffb8e0057c
- BUILDINFO: QEMU upstream commit=8bff6989bd0bafcc0ddf859c23ce6a2ff21a80ff
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Add 'bios' option to xend/xm toolstack for HVM guests (Bhavesh Davda) 
- xen.spec: enable OVMF (Zhigang Wang)  [Orabug: 26248846]
- xen/disk: don't leak stack data via response ring (Jan Beulich) 
[Orabug: 26198945]

[4.4.4-137.el6]
- BUILDINFO: xen commit=03fbb2dedc86fb742f1066ffaef76e1c68edccd3
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- python/vnuma: Use memmax_mb value when constructing node_memsz (Konrad 
Rzeszutek Wilk) - python/vNUMA: When creating a list of cores (and 
siblings) account for all CPUs. (Konrad Rzeszutek Wilk)  [Orabug: 26223159]
- python/vNUMA: Creation of nodeload would only pick first CPU of a NODE 
(Konrad Rzeszutek Wilk) - Partial revert "xend: use dom0 vcpus for vnuma 
guests" (Konrad Rzeszutek Wilk)  [Orabug: 26223159]
- vNUMA: propagate topology down to domain memory allocation (Elena 
Ufimtseva)  [Orabug: 26037786]
- xc: move code around to reuse common parts (Elena Ufimtseva)  [Orabug: 
26037786]
- xc: use xc_hvm_build_args for memory config passing (Elena Ufimtseva) 
[Orabug: 26037786]

[4.4.4-136.el6]
- BUILDINFO: xen commit=901fe4364deb69a6a803f540f03c1d8cf418dbc0
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xen-numa: Add a heatmap. (Konrad Rzeszutek Wilk)  [Orabug: 26037786]
- xen-numa: Diagnostic tool to figure out NUMA issues. (Konrad Rzeszutek 
Wilk)  [Orabug: 26037786]
- libxc: Add xc_list_numa (Konrad Rzeszutek Wilk)  [Orabug: 26037786]
- x86:domctl: Add XEN_DOMCTL_get_numa_ranges (Konrad Rzeszutek Wilk) 
[Orabug: 26037786]
- xen-mceinj: Loop around xc_get_pfn_list (Konrad Rzeszutek Wilk) 
[Orabug: 26037786]
- libxc: libxc: Use XENDOMCTL_get_memlist properly (Konrad Rzeszutek 
Wilk)  [Orabug: 26037786]
- xen/x86: XENDOMCTL_get_memlist: Make it work (Konrad Rzeszutek Wilk) 
[Orabug: 26037786]
- dom0_vcpus_pin/numa: Consider the rest of left-over CPUs. (Konrad 
Rzeszutek Wilk)  [Orabug: 26089036]
- python/vnuma: Take into account paused (or not yet running) vCPUs of 
guests (Konrad Rzeszutek Wilk)  [Orabug: 26250117]

[4.4.4-135.el6]
- BUILDINFO: xen commit=5ba391cfacd7fa7a0629ce6055269a2b301c7d2f
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- python/xc: When getting CPU topology get more than 255 CPUs. (Konrad 
Rzeszutek Wilk)  [Orabug: 26261494]

[4.4.4-134.el6]
- BUILDINFO: xen commit=6fad8c911499ad80dfb73859744fa65111735a07
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- livepatch: Wrong usage of spinlock on debug console. (Konrad Rzeszutek 
Wilk)  [Orabug: 26248274]
- xend/vNUMA: Fix error when NUMA node has no memory. (Konrad Rzeszutek 
Wilk)  [Orabug: 26188839]

[4.4.4-133.el6]
- BUILDINFO: xen commit=f6b6f9a4e9d69dfafa7ad54badcb0475f72d64f0
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- acpi: enlarge NUM_FIXMAP_ACPI_PAGES to support larger scale boards 
(Zhang Bo)

[4.4.4-132.el6]
- BUILDINFO: xen commit=3e2d7e037d96d790fdef7855e8a9b11b7a74c1e2
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: use dom0 vcpus for vnuma guests (Elena Ufimtseva)  [Orabug: 
26223159]
- xend: vnuma: fix vcpus number check (Elena Ufimtseva)  [Orabug: 26224064]
- xend: fix exceptions format for vNUMA errors (Elena Ufimtseva) 
[Orabug: 26033122]

[4.4.4-131.el6]
- BUILDINFO: xen commit=f32f152497dfa82a6107ef0d964584043dd3db93
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86: Make dom0_numa_cpu_init opt_dom0_vcpus_pin_setup be __init 
(Konrad Rzeszutek Wilk) - xend: raise exceptions if vNUMA guest cannot 
be constructed (Elena Ufimtseva) - xen: check if vNUMA topology is 
correct (Elena Ufimtseva)  [Orabug: 26109642]
- xend: make vNUMA warnings a bit more relevant (Elena Ufimtseva) - 
xend: relax vcpus number checks if smt is off (Elena Ufimtseva) - xend: 
fix apicid layout on vnuma failure (Elena Ufimtseva)  [Orabug: 26109642]

[4.4.4-130.el6]
- BUILDINFO: xen commit=650b285e661e78d321071b83b6f64ee277b50f85
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: add "vnuma" global config value. (Konrad Rzeszutek Wilk) 
[Orabug: 26089036]
- xend/pci: Respect PCI devices taking their time to do FLR (Konrad 
Rzeszutek Wilk)  [Orabug: 26032540]
- dom0_vcpus_pin=[cpu-cpu],[cpu] support. (Konrad Rzeszutek Wilk) 
[Orabug: 25559771]
- dom0_vcpus_pin: Include 'numa' support. (Konrad Rzeszutek Wilk) 
[Orabug: 25559771]

[4.4.4-129.el6]
- BUILDINFO: xen commit=c33f380b06b3a3c2abb2cdde4a9e0d046c9beb27
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Merge branch 'ksplice-ovm-3.4' of git://ca-git/ovm-devel into 
ovm-3.4.4 (Konrad Rzeszutek Wilk)  [Orabug: 25752156]

[4.4.4-128.el6]
- BUILDINFO: xen commit=8ccc41054b882d014b487613a0ed699e9cc2cc00
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Increase VM suspend timeout in xend from 60 to 300 seconds to 
accommodate Windows guests. Log a message every 10 seconds instead of 
every second while waiting for a suspending VM. (Alexandre Khodakovski) 
[Orabug: 25801187]

[4.4.4-127.el6]
- BUILDINFO: xen commit=822938f96e56d45dcc27fcba939bd94e95a28eb7
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Merge branch 'ovm-3.4.4-ksplice' of 
git://ca-git.us.oracle.com/ovm-devel into ovm-3.4.4 (Konrad Rzeszutek 
Wilk)  [Orabug: 25752156]
- x86/do_invalid_op() should use is_active_kernel_text() rather than 
having its (Konrad Rzeszutek Wilk) - xen: arch/x86/bug: don't encode 
line number into displacements. (Jamie Iles)  [Orabug: 25752156]
- KSPLICE: xen: add ssize_t type. (Gregory Herrero)  [Orabug: 25752156]
- KSPLICE: xen: module: add module_refcount() function. (Gregory 
Herrero)  [Orabug: 25752156]
- KSPLICE: xen: module: helper to find module containing address in 
.text only. (Gregory Herrero)  [Orabug: 25752156]
- KSPLICE: support -ffunction-sections and -fdata-sections (Blaise 
Boscaccy)  [Orabug: 25752156]
- KSPLICE: Makefile: add rules to dump C/LD/AFLAGS. (Quentin Casasnovas) 
  [Orabug: 25752156]
- xen: stop_machine: fill fn_result only in case of error. (Gregory 
Herrero)  [Orabug: 25752156]
- xen/tests: module parameter tester. (Gregory Herrero)  [Orabug: 25752156]
- xen: module: parse module parameters. (Gregory Herrero)  [Orabug: 
25752156]
- xen: module: add parameters code from Linux v4.9. (Gregory Herrero) 
[Orabug: 25752156]
- xen: string: add few helpers from kernel side. (Gregory Herrero) 
[Orabug: 25752156]
- xen: module: rm module usage on failure. (Gregory Herrero)  [Orabug: 
25752156]
- xen: module: register symbol_lookup callback. (Gregory Herrero) 
[Orabug: 25752156]
- xen: module: implement is_module(). (Jamie Iles)  [Orabug: 25752156]
- xen: add support for attributes. (Jamie Iles)  [Orabug: 25752156]
- xen: module: rework try_module_get() so it can be used on vanished 
modules. (Quentin Casasnovas)  [Orabug: 25752156]
- xen: build: modules: add symbol lookup test. (Gregory Herrero) 
[Orabug: 25752156]
- xen: module: check for duplicate global symbols. (Gregory Herrero) 
[Orabug: 25752156]
- xen: module: add possiblity to lookup symbol in loaded modules. 
(Gregory Herrero)  [Orabug: 25752156]
- xen: module: track module dependencies. (Gregory Herrero)  [Orabug: 
25752156]
- xen: elfloader: look symbols in caller specified callback. (Gregory 
Herrero)  [Orabug: 25752156]
- xen: module: add a test for exception table entries in modules. (Jamie 
Iles)  [Orabug: 25752156]
- xen: module: add a test for bug frames in modules. (Jamie Iles) 
[Orabug: 25752156]
- xen: module: register a virtual region, ex_table, bug frames + 
alternatives. (Jamie Iles)  [Orabug: 25752156]
- xen: tools: xen-lsmod: initial commit. (Quentin Casasnovas)  [Orabug: 
25752156]
- xen: tools: xen-rmmod: initial commit. (Quentin Casasnovas)  [Orabug: 
25752156]
- xen: tools: xen-insmod: initial commit. (Quentin Casasnovas)  [Orabug: 
25752156]
- xen: build: strip obj-y when checking if it is empty. (Quentin 
Casasnovas)  [Orabug: 25752156]
- xen: build: modules: add build infrastructure to build modules. 
(Quentin Casasnovas)  [Orabug: 25752156]
- xen: build: allow custom C/AFLAGS per compilation unit. (Quentin 
Casasnovas)  [Orabug: 25752156]
- xen: module: handle empty modules gracefully (Vegard Nossum)  [Orabug: 
25752156]
- xen: module: add generic module loading sysctl interface. (Quentin 
Casasnovas)  [Orabug: 25752156]
- xen: elfloader: relocate sections into segments. (Quentin Casasnovas) 
[Orabug: 25752156]
- xen: elfloader: initialize vmalloc space so we can map modules. 
(Quentin Casasnovas)  [Orabug: 25752156]
- xen: elfloader: ignore the _GLOBAL_OFFSET_TABLE_ when resolving 
symbols. (Quentin Casasnovas)  [Orabug: 25752156]
- xen: arch/x86/symbols: record all symbols with CONFIG_ELFLOADER. 
(Quentin Casasnovas)  [Orabug: 25752156]
- xen: elfloader: don't refuse OSABI_LINUX. (Quentin Casasnovas) 
[Orabug: 25752156]
- xen: elfloader: support absolute 32bits signed and unsigned 
relocations. (Quentin Casasnovas)  [Orabug: 25752156]
- xen: elfloader: decouple from live patching infrastructure. (Quentin 
Casasnovas)  [Orabug: 25752156]
- stdarg: add va_copy definition. (Blaise Boscaccy)  [Orabug: 25752156]
- xen: stdbool.h: use typedef to define bool. (Gregory Herrero) 
[Orabug: 25752156]
- x86/stack: avoid peeking into unmapped guard pages when dumping Xens 
stack (Andrew Cooper)  [Orabug: 25752156]
- xen: guestcopy: Provide an helper to safely copy string from guest 
(Julien Grall)  [Orabug: 25752156]

[4.4.4-126.el6]
- BUILDINFO: xen commit=ffde49660a0b4695fb522fbfd0a2a78c7c916494
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86/time: extend "tsc" param with "stable:socket" (Joao Martins) 
[Orabug: 23585649]
- x86/time: implement PVCLOCK_TSC_STABLE_BIT (Joao Martins)  [Orabug: 
23585649]
- x86/time: implement tsc as clocksource (Joao Martins)  [Orabug: 23585649]
- x86/time: refactor read_platform_stime() (Joao Martins)  [Orabug: 
23585649]
- x86/time: refactor init_platform_time() (Joao Martins)  [Orabug: 23585649]
- public/xen.h: add flags field to vcpu_time_info (Joao Martins) 
[Orabug: 23585649]
- x86/time: always count s_time from Xen boot (Tim Deegan)  [Orabug: 
23585649]
- xen/x86: introduce nr_sockets (Joao Martins)  [Orabug: 23585649]

[4.4.4-125.el6]
- BUILDINFO: xen commit=5d6782af3a4e24942c5f1d1bfa0c136825cb8e61
- BUILDINFO: QEMU upstream commit=44c5f0a55d9a73e592426c33ce5705c969681955
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: Don't expose 'pxm' entries if vnuma is not set. (Konrad 
Rzeszutek Wilk) - xm: Print device topology with "info -n". (Karl 
Heubaum)  [Orabug: 25368257]
- python/xc: dev_to_node support for topologyinfo(). (Karl Heubaum) 
[Orabug: 25368257]
- xl: "info -n" should omit invalid NUMA nodes. (Karl Heubaum) - libxl: 
Correctly check the return value from malloc(). (Karl Heubaum) - libxl: 
Support 'pxm' on pci guest config override. (Konrad Rzeszutek Wilk) 
[Orabug: 25368257]
- libxl: Expose pxm-X on 'pci' XenBus entries. (Konrad Rzeszutek Wilk) 
[Orabug: 25368257]
- xend: Don't run the watch if there is nothing in the aerWatch (Konrad 
Rzeszutek Wilk) - xend: Support 'pxm' on pci guest config override. 
(Konrad Rzeszutek Wilk)  [Orabug: 25368257]
- xend: Expose pxm-X on 'pci' XenBus entries. (Konrad Rzeszutek Wilk) 
[Orabug: 25368257]
- xend, libxl, x86/topology: remove 2 * APIC_ID with smt (Joao Martins) 
[Orabug: 25853596]
- xend, libxl: account for vnodes when smt=1 (Joao Martins)  [Orabug: 
25853596]
- x86/hvm, hvmloader: fix apicid layout for smt (Joao Martins)  [Orabug: 
25853596]
- xm: add support for vNUMA (Elena Ufimtseva)  [Orabug: 25368257]
- xc: parse and prepare to set vNUMA (Elena Ufimtseva)  [Orabug: 25368257]
- xc: add xc_domain_initvnuma to support xend vNUMA (Elena Ufimtseva) 
[Orabug: 25368257]
- libxc: fill lowmem_end and and highmem for xc_hvm_build_args (Elena 
Ufimtseva)  [Orabug: 25741411]
- libxc: unify handling of vNUMA layout (Wei Liu)  [Orabug: 25741411]
- handle XENMEM_get_vnumainfo in compat_memory_op (Wei Liu)  [Orabug: 
25741411]
- libxl: copy function for builtin types (Wei Liu)  [Orabug: 25741411]
- xl: handle empty vnuma configuration (Wei Liu)  [Orabug: 25741411]
- libxc: introduce xc_domain_getvnuma (Wei Liu)  [Orabug: 25741411]
- libxc: fix vNUMA memory allocation (Wei Liu)  [Orabug: 25741411]
- xl: error out if vNUMA specifies more vcpus than pcpus (Wei Liu) 
[Orabug: 25741411]
- xl: fix vNUMA vdistance parsing (Wei Liu)  [Orabug: 25741411]
- libxc: allow empty memory nodes in vNUMA (Boris Ostrovsky)  [Orabug: 
25741411]
- xl: fix vcpus to vnode assignement in config file (Dario Faggioli) 
[Orabug: 25741411]
- libxlu: introduce new APIs (Wei Liu)  [Orabug: 25741411]
- libxlu: record location when parsing values (Wei Liu)  [Orabug: 25741411]
- libxlu: nested list support (Wei Liu)  [Orabug: 25741411]
- libxlu: don't crash on empty lists (Jan Beulich)  [Orabug: 25741411]
- libxlu: rework internal representation of setting (Wei Liu)  [Orabug: 
25741411]
- libxl: fix HVM vNUMA (Wei Liu)  [Orabug: 25741411]
- libxc: rework vnuma bits in setup_guest (Wei Liu)  [Orabug: 25741411]
- libxc/libxl: fill xc_hvm_build_args in libxl (Wei Liu)  [Orabug: 25741411]
- make dumping vcpu info look better (Dario Faggioli)  [Orabug: 25741411]
- make two memory hypercalls vNUMA-aware (Wei Liu)  [Orabug: 25741411]
- factor out construct_memop_from_reservation (Wei Liu)  [Orabug: 25741411]
- libxlu: avoid having two definitions of XLU_ConfigList (Wei Liu) 
[Orabug: 25741411]
- xl: vNUMA support (Wei Liu)  [Orabug: 25741411]
- libxlu: introduce new APIs (Wei Liu)  [Orabug: 25741411]
- libxlu: rework internal representation of setting (Wei Liu)  [Orabug: 
25741411]
- xl: introduce xcalloc (Wei Liu)  [Orabug: 25741411]
- libxl: define LIBXL_HAVE_VNUMA (Wei Liu)  [Orabug: 25741411]
- libxl: disallow memory relocation when vNUMA is enabled (Wei Liu) 
[Orabug: 25741411]
- libxl: build, check and pass vNUMA info to Xen for HVM guest (Wei Liu) 
  [Orabug: 25741411]
- libxc: allocate memory with vNUMA information for PV guest (Wei Liu) 
[Orabug: 25741411]
- libxc: allocate memory with vNUMA information for HVM guest (Wei Liu) 
[Orabug: 25741411]
- libxc: indentation change to xc_hvm_build_x86.c (Wei Liu)  [Orabug: 
25741411]
- libxl: build, check and pass vNUMA info to Xen for PV guest (Wei Liu) 
[Orabug: 25741411]
- libxl: functions to build vmemranges for PV guest (Wei Liu)  [Orabug: 
25741411]
- libxl: x86: factor out e820_host_sanitize (Wei Liu)  [Orabug: 25741411]
- libxl: introduce libxl__vnuma_config_check (Wei Liu)  [Orabug: 25741411]
- libxl: add vmemrange to libxl__domain_build_state (Wei Liu)  [Orabug: 
25741411]
- libxl: introduce vNUMA types (Wei Liu)  [Orabug: 25741411]
- libxc: add p2m_size to xc_dom_image (Wei Liu)  [Orabug: 25741411]
- libxc: duplicate snippet to allocate p2m_host array (Wei Liu) 
[Orabug: 25741411]
- vNUMA: validate XEN_DOMCTL_setvnumainfo input (Jan Beulich)  [Orabug: 
25741411]
- hvmloader: construct SLIT (Wei Liu)  [Orabug: 25741411]
- hvmloader: construct SRAT (Wei Liu)  [Orabug: 25741411]
- hvmloader: retrieve vNUMA information from hypervisor (Wei Liu) 
[Orabug: 25741411]
- x86: dump vNUMA information with debug key 'u' (Elena Ufimsteva) 
[Orabug: 25741411]
- vNUMA: rename interface structures (Jan Beulich)  [Orabug: 25741411]
- tools/xl: Call init function for libxl_bitmap (Uma Sharma)  [Orabug: 
25741411]
- move XENMEM_get_vnumainfo out of tools-only section of public/memory.h 
(Jan Beulich)  [Orabug: 25741411]
- xl: add 'trim' and 'split_string_into_pair' functions (David Scott) 
[Orabug: 25741411]
- xl: add 'xstrdup' next to 'xrealloc' (David Scott)  [Orabug: 25741411]
- libxc: Introduce xc_domain_setvnuma to set vNUMA (Elena Ufimtseva) 
[Orabug: 25741411]
- xen: vnuma topology and subop hypercalls (Elena Ufimtseva)  [Orabug: 
25741411]
- libxl: Change default for b_info->{cpu, node}map to "not allocated" 
(Dario Faggioli)  [Orabug: 25741411]
- hvmloader: add helper functions to get/set HVM params (David Vrabel) 
[Orabug: 25741411]
- derive NUMA node affinity from hard and soft CPU affinity (Dario 
Faggioli)  [Orabug: 25741411]
- sched: introduce soft-affinity and use it instead d->node-affinity 
(Dario Faggioli)  [Orabug: 25741411]
- sched: rename v->cpu_affinity into v->cpu_hard_affinity (Dario 
Faggioli)  [Orabug: 25741411]
- libxl_internal.h: move / add some libxl defbool #define here (Wei Liu) 
  [Orabug: 25741411]
- libxl: fix memory leak in libxl_cpuid_dispose (Wei Liu)  [Orabug: 
25741411]
- add the facility to limit ranges per rangeset (Paul Durrant)  [Orabug: 
25741411]
- libxl: bail from placement on non-NUMA boxes (Dario Faggioli) 
[Orabug: 25741411]
- tools/libxl: Introduce libxl__malloc() (Andrew Cooper)  [Orabug: 25741411]
- tools/libxl: Correct libxl__zalloc() to take an unsigned number of 
bytes (Andrew Cooper)  [Orabug: 25741411]
- x86: correct create_bounce_frame (tagged with CVE number) (Boris 
Ostrovsky)  [Orabug: 25918367]  {CVE-2017-8905}
- x86: discard type information when stealing pages (tagged with CVE 
number) (Boris Ostrovsky)  [Orabug: 25918337]  {CVE-2017-8904}
- multicall: deal with early exit conditions (tagged with CVE number) 
(Boris Ostrovsky)  [Orabug: 25918274]  {CVE-2017-8903}

[4.4.4-124.el6]
- BUILDINFO: xen commit=72204c60101d0381c0724eb53e756eb3d01f89c4
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Merge branch 'ovm-3.4.4' of git://ca-git.us.oracle.com/xen into 
ovm-3.4.4 (build) - tools/libxc: Set max_elem to zero in 
xc_lockprof_query_number() (Boris Ostrovsky)  [Orabug: 20492963]

[4.4.4-123.el6]
- BUILDINFO: xen commit=483b9ffd198554342e13e8c982132374fd20a3b2
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- x86: correct create_bounce_frame (Boris Ostrovsky)  [Orabug: 25918367]
- x86: discard type information when stealing pages (Boris Ostrovsky) 
[Orabug: 25918337]
- multicall: deal with early exit conditions (Boris Ostrovsky)  [Orabug: 
25918274]

[4.4.4-122.el6]
- BUILDINFO: xen commit=c4eaaf85366633a90bf7c7f9cfa486dd9b2c4502
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- Xend DevController: Read hotplug-status value busy if provided by 
block back driver (Niranjan Patil)  [Orabug: 25498155]
- Xend: add option for discard support in xm disk configuration 
(Niranjan Patil)

[4.4.4-121.el6]
- BUILDINFO: xen commit=dd9d9cf5f2c1084876e085fb2361b2d44f7805e6
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- kexec: Add spinlock for the whole hypercall. (Konrad Rzeszutek Wilk) 
[Orabug: 25527136]
- kexec: clear kexec_image slot when unloading kexec image (Bhavesh 
Davda)  [Orabug: 25527136]

[4.4.4-120.el6]
- BUILDINFO: xen commit=269c39d2a24a9f59d55fbea6289407e14bc84b00
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- cirrus: add blit_is_unsafe call to cirrus_bitblt_cputovideo (Gerd 
Hoffmann)  [Orabug: 25533541] {CVE-2017-2620} {CVE-2017-2620}
- cirrus: fix oob access issue (CVE-2017-2615) (Li Qiang)  [Orabug: 
25533433]  {CVE-2017-2615} {CVE-2017-2615}
- cirrus/vnc: zap drop bitblit support from console code. (Gerd 
Hoffmann)  [Orabug: 25718334]  {CVE-2016-9603}
- display: cirrus: ignore source pitch value as needed in blit_is_unsafe 
(Bruce Rogers)  [Orabug: 25533541]  {CVE-2017-2620}
- oxenstored: trim history in the frequent_ops function (Thomas Sanders) 
  [Orabug: 25798837]
- oxenstored transaction conflicts: improve logging (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: don't wake to issue no conflict-credit (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: do not commit read-only transactions (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: allow self-conflicts (Thomas Sanders)  [Orabug: 25798837]
- oxenstored: blame the connection that caused a transaction conflict 
(Jonathan Davies)  [Orabug: 25798837]
- oxenstored: track commit history (Jonathan Davies)  [Orabug: 25798837]
- oxenstored: discard old commit-history on txn end (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: only record operations with side-effects in history 
(Jonathan Davies)  [Orabug: 25798837]
- oxenstored: support commit history tracking (Jonathan Davies) 
[Orabug: 25798837]
- oxenstored: add transaction info relevant to history-tracking 
(Jonathan Davies)  [Orabug: 25798837]
- oxenstored: ignore domains with no conflict-credit (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: handling of domain conflict-credit (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: comments explaining some variables (Thomas Sanders) 
[Orabug: 25798837]
- oxenstored: allow compilation prior to OCaml 3.12.0 (Jonathan Davies) 
[Orabug: 25798837]
- oxenstored: log request and response during transaction replay 
(Jonathan Davies)  [Orabug: 25798837]
- oxenstored: replay transaction upon conflict (Jonathan Davies) 
[Orabug: 25798837]
- oxenstored: move functions that process simple operations (Jonathan 
Davies)  [Orabug: 25798837]
- oxenstored: keep track of each transaction's operations (Jonathan 
Davies)  [Orabug: 25798837]
- oxenstored: refactor request processing (Jonathan Davies)  [Orabug: 
25798837]
- oxenstored: remove some unused parameters (Jonathan Davies)  [Orabug: 
25798837]
- oxenstored: refactor putting response on wire (Jonathan Davies) 
[Orabug: 25798837]
- oxenstored: add a safe net mechanism for existing ill-behaved clients 
(Zheng Li)  [Orabug: 25798837]
- oxenstored: only process domain connections that notify us by events 
(Zheng Li)  [Orabug: 25798837]
- oxenstored: enable domain connection indexing based on eventchn port 
(Zheng Li)  [Orabug: 25798837]
- oxenstored: use hash table to store socket connections (Zheng Li) 
[Orabug: 25798837]
- oxenstored: catch the error when a connection is already deleted 
(Zheng Li)  [Orabug: 25798837]
- oxenstored: perform a 3-way merge of the quota after a transaction 
(Jerome Maloberti)  [Orabug: 25798837]
- oxenstored: exempt dom0 from domU node quotas (Vincent Bernardoff) 
[Orabug: 25798837]
- mm: Don't check for waiters when scrubbing (Boris Ostrovsky)  [Orabug: 
25860374]

[4.4.4-119.el6]
- BUILDINFO: xen commit=a2154a806f302e82a88d720bf29e70b94250b955
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- memory: properly check guest memory ranges in XENMEM_exchange handling 
(Boris Ostrovsky)  [Orabug: 25799098]  {CVE-2017-7228}
- xenstored: Log when the write transaction rate limit bites (Ian 
Jackson)  [Orabug: 25798837]
- xenstored: apply a write transaction rate limit (Ian Jackson) 
[Orabug: 25798837]

[4.4.4-118.el6]
- BUILDINFO: xen commit=4a87a4ad87b19713948976a2e12bc080fd6ff370
- BUILDINFO: QEMU upstream commit=fcd17fdf18b95a9e408acc84f6d2b37cf3fc0335
- BUILDINFO: QEMU traditional 
commit=346fdd7edd73f8287d0d0a2bab9c67b71bc6b8ba
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: do not acquire vm running lock at start after soft_reset 
(Zhigang Wang)  [Orabug: 25729452]

[4.4.4-117.el6]
- BUILDINFO: xen commit=195df020b96c2b8b22f57c9f2a60044cc99aa11d
- BUILDINFO: QEMU upstream commit=2e4e0a805aeb448242b43399e0853b851bccde4e
- BUILDINFO: QEMU traditional 
commit=d9ba4c53b14ebf9a0613b5638f90d95489622f0c
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xend: fix vif device ID allocation (Zhigang Wang)  [Orabug: 25692157]

[4.4.4-116.el6]
- BUILDINFO: xen commit=c250840c771113c9cf15f03d453b3c6a6e58091a
- BUILDINFO: QEMU upstream commit=f663d3dd4e968756d33e29cb2c2c956cabbdd4ca
- BUILDINFO: QEMU traditional 
commit=d9ba4c53b14ebf9a0613b5638f90d95489622f0c
- BUILDINFO: IPXE commit=9a93db3f0947484e30e753bbd61a10b17336e20e
- BUILDINFO: SeaBIOS commit=7d9cbe613694924921ed1a6f8947d711c5832eee
- xm: Fix the error message displayed by 'xm create ...' (Venu 
Busireddy)  [Orabug: 25667536]
- xm: expand pci hidden devices tools (Venu Busireddy)  [Orabug: 25576024]
- xend: fix waitForSuspend (Zhigang Wang)  [Orabug: 25638583]
- xen: Bump max number of processors to 2048 (Boris Ostrovsky)  [Orabug: 
24288531]
- acpi: switch to dynamic mapping at SYS_STATE_boot (Boris Ostrovsky) 
[Orabug: 24288531]



More information about the Oraclevm-errata mailing list