Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/QubesOS/qubes-vmm-xen

Qubes component: vmm-xen
https://github.com/QubesOS/qubes-vmm-xen

Merge remote-tracking branch 'origin/main'

* origin/main:
Temporarily switch to a hash file for download verification

21602819df64cb9f654bbb3dcebeb1b5102553b5 authored 9 months ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.3-4

7ebe19ebf18511a8989ef8e38b4ff952a5aee506 authored 9 months ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-452 patches

323d22707cf56529f667229eefd259dca6fe25ac authored 9 months ago by Marek Marczykowski-Górecki <[email protected]>
Temporarily switch to a hash file for download verification

The signing key still uses SHA1, which is rejected by sequoia-sq. Switch
to hash file until the ...

606f99ae86189ece9a9ec394de1f56529947f7d6 authored 10 months ago by Marek Marczykowski-Górecki <[email protected]>
Include patches from stable-4.17 branch

Some of them were already backported, but there are few more relevant
fixes. This may also ease ...

f22008ff1f41a91213383b6ce532548bf2c26b4c authored 10 months ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.3-3

8eeb295af3f7f3d14d13257ea33cb4a72dcae374 authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
Backport IVMD fix

See patch description

4ae2033b6ca4a3bec4cbb161e57cd85fdc59dd66 authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.3-2

f67c3d809570027d7432cda8a18390a0921b141a authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-449 patch

a98e7e7a7e9ffb198c7b0b8614f13e147022f58c authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
Update Xen config to 4.17.3, enable DOITM

cacb1a165abd906971e2d1762409f2d71e62a8a5 authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
Update to Xen 4.17.3

Drop patches included upstream already, refresh SOURCE_DATE_EPOCH patch
to resolve conflict.

c09047e94ef08928be689e5769582a160bf3f802 authored 11 months ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-8

b567bd91d0cda0b65c6dd7f28468f97cbb85f0c7 authored 12 months ago by Marek Marczykowski-Górecki <[email protected]>
Fix guest memory corruption caused by hvmloader

Running qemu upstream in stubdomain missed one hvmloader setting, fix it
now.

QubesOS/qubes-iss...

38be433d0a176ad843022d496cfdfe64c61e1ded authored 12 months ago by Marek Marczykowski-Górecki <[email protected]>
Backport XHCI console support for AMD

QubesOS/qubes-issues#6834

631ca94b39037ca6920d218c5a5abcd8ac6a19cd authored 12 months ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-7

20434253f189f60012eb8faddce2a1bb41bb2087 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/171'

* origin/pr/171:
Disable annobin for the hypervisor build

7677f00d132de39b6a6d01ee76b5e8ea1710dab2 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-6

1a02560699a0327684e638382be7a3f2252c5713 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Backport cpupool fix

Related to QubesOS/qubes-issues#8737

973d80cc04cbb077436aa4d07a4ee7d43b6f6bad authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
backport: x86/x2apic: introduce a mixed physical/cluster mode

Fixes QubesOS/qubes-issues#8111

7d397a83e71b31e3dff0d1fc8ae38f8ccc6554f3 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Disable annobin for the hypervisor build

The .annobin.notes section gets placed at the start of xen.efi, which
(for unclear reasons) brea...

822645c9d898140d8243107b89938a4fe4e16929 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-5

bd8302945c876f9c53590f69cf89622af74d5748 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-446 patch

d8d557c978aac335e5da3277273893e7ed3ed7e9 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-4

719daa6f656ffeb6d519a0b6af9e0f7e4f885736 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Merge branch 'msix'

* msix:
Apply patches for MSI-X support with stubdomain

4e6714f95c8f0670c20d4a646cf0a35dc0e083cc authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/169'

* origin/pr/169:
Compress old console logs

5cf456b19807f5552f77d0097c850e16f2f02cf4 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
rpm: remove duplicated ldconfig call

And avoid sending a comment as an input for ldconfig.

7c46662952853357d2f9f815a7e84767eaf0d7de authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-3

50d46d93518c0ed31fe7eb6d03e2c7a8c172d79a authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-442 patch

641f36bee0080aa992ba8a9bf7bfebe09ebee0dd authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply patches for MSI-X support with stubdomain

Fixes QubesOS/qubes-issues#4799
Fixes QubesOS/qubes-issues#7057
Fixes QubesOS/qubes-issues#7052

5b6bf0628d1d1ca1fee6f52c89383e2d831b541e authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Compress old console logs

They may grow quite big in some cases, and are very compressible.

9596786c2540b175903a894a20c904c63afd8922 authored about 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.2-2

5cd1d9157e8c11ba2f774919c2b21fc81603fbd7 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Switch back to official tarballs

57e8e741df44f2171be458812b1f990514b7f51b authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Backport fix for OpenBSD 7.3 booting

Fixes QubesOS/qubes-issues#8502

a480b9e211bdb383c340b98877369015b7a13c12 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-439 fix

d46117635980e73fc4edc164a136e3c1f6260f2e authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Update to 4.17.2

Temporarily use a git snapshot, until upstream provides proper tarballs.

0cb44dddf66f8fa353f47733ad6d9ecd1b49ce0a authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Rebase patches on top of 4.17.2

And drop those already included upstream.

fbc7e445fdf5cc0a8895382f861231cf611d7d07 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.1-4

82eaa96959cd0caab27a6117da66974d87518d9a authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply fix for the original XSA-433 patch

cd1ccd8fc7730b738b992bee12503a58e1fd7f69 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.1-3

06d5e309fe7bdcfabad8fe8ac30ef8998ede4467 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-433 fix

Microcode update is available only for some models at this moment, so
include the workaround pat...

172ff3648b4500a676de836946a6e8edd0e5a704 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.1-2

8d8f66a3868ff8645ed044d35a398c37c49c6650 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Use upstream approach for publishing ARCH_CAPS to guests

Replace custom patch with proper upstream implementation.

7d58d34b9a30ac70c71fb39f7e9bd5e944b1088c authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
rpm: remove xen-qubes-vm subpackage

It isn't used anymore, VMs use distribution-native Xen packages fully.

6548eacfb48f4620b0c5844e4fe5fa4c4009c864 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
ci: update INSTALL_EXCLUDE variable name

c18c73e4e3f9f7e8aa9a726c8f91f7c49ee3eb58 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
Backport few patches

Backport serial console fix, and a build fix with GCC 13 (relevant for
Archlinux).

88d40a1e98b31ae981d38f3a035db77f45939d96 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.1-1

Drop patches included upstream already, update context of some existing
patches.
Include also XS...

3e05028c1ec6c4f902794169f384e43c928e8c14 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-9

d3f10e4cbe391c0f32339290e94b74df5f5fd467 authored over 1 year ago by Marek Marczykowski-Górecki <[email protected]>
gitlab-ci: remove 4.1

df4f8481b7d3327f9d28d8e3169d400b8c013215 authored over 1 year ago by Frédéric Pierret (fepitre) <[email protected]>
Rework Archlinux packaging

73913a378011b73709d01285f9cc2c429d9cbd1b authored almost 2 years ago by Frédéric Pierret (fepitre) <[email protected]>
version 4.17.0-8

c9cbdde5b9d908712050508824a061739560e6e3 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/161'

* origin/pr/161:
Drop extra ELF notes

99c097f3a43abc245b84b960072ebfefb9ee55f8 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Apply XSA-426 fix

Technically it doesn't affect Qubes OS, as it has smt=0. But still apply
the patch for the sake ...

5aaac34885f4833e5a996260e0b4ebefe61bbd77 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Drop extra ELF notes

The ELF notes on multiboot binary are broken, remove them to unbreak
booting from Heads (via kex...

b7b3cc567b6c59ad9d1fb4a31aaaf555d6053ec8 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-7

b12aabb74558b02272f4600e4dc2ed7efb9e635e authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/159'

* origin/pr/159:
Recover some performance from unneeded speculative workarounds

7287e587a435fe7841623ec7e3610d6ac8962313 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/157'

* origin/pr/157:
Backport workaround for broken CET-SS on some parts

d58ae31b00a6c652a58ca75c1a8d23f19d6e3b70 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/158'

* origin/pr/158:
Include support for Intel HWP

4e7bc22554d83c9fa571dcad731ee8d014932b96 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Recover some performance from unneeded speculative workarounds

Tell guest kernel what fixes are already available in the hardware, so
it can turn off some of t...

a3c7fca96c636d198a09daee1963c03dd1c901ec authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Include support for Intel HWP

Hardware-managed P-states (when supported) results significantly smaller
power consumption accor...

4a97122e26d1d7a24553b7cf37b193151a45a330 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-6

47e91327194eea44cb732a6232c93973322b7db2 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
rpm: re-add R: seabios-bin

It was erroneously removed during spec file refresh.

95d8b7192b24e135e341be9014b7406e4771176a authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Backport workaround for broken CET-SS on some parts

See patches description for detail.

8cdd56870d1d6ae030c1f5c270e196b5948f64b3 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-5

1fd7978a1b8458e0b2a509db65460eb045e12a93 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/156'

* origin/pr/156:
Add patch for Python >= 3.10 support

60e99bd49143d31ce403cd43ad956bf5981b2504 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Add patch for Python >= 3.10 support

QubesOS/qubes-issues#6982

437ad1f29e35670029eea73ddb1a882c99f7fe67 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Activate Data Operand Independent Timing Mode by default

See patch for details.

5895aecb39561cc2481635f0ef97890d3fea54c7 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
version 4.17.0-4

c85f4e1ac4eeedeed087ea04df5636519723e79e authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/151'

* origin/pr/151:
xen backport: prevent overflow with high frequency TSC

b1c1756a643e8894189c3c32221e2c1cc50b0a3b authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/154'

* origin/pr/154:
Do not override stub grub.cfg on EFI partition

92a1877493d21b483e86aecb3103dd16914fd952 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge remote-tracking branch 'origin/pr/153'

* origin/pr/153:
gitlab-ci: don't build for Debian
Remove build for CentOS
Support for Fed...

0630523332522496c65ce230c5b5656f93647553 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
ci: add openqa repo build

f4347ecaaf7e5aa6be06577946544f91ad95af30 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
gitlab-ci: don't build for Debian

a069bd366a88d6719d826e822eda9e44386264a9 authored almost 2 years ago by Frédéric Pierret (fepitre) <[email protected]>
Remove build for CentOS

We will try to have upstream build in EPEL or on COPR.

cfe6a03b45964ee73399357be229c5b0fb3995b4 authored almost 2 years ago by Frédéric Pierret (fepitre) <[email protected]>
Support for Fedora 37 build

- Sync spec file with upstream

2a71af592796372c7f0d4fa8abb7cb86a986d4a6 authored almost 2 years ago by Frédéric Pierret (fepitre) <[email protected]>
Do not override stub grub.cfg on EFI partition

Grub2 in R4.2 is made to include grub.cfg from primary /boot partition,
even on EFI systems - so...

13db9576495ff8182973e6cdbc658e4a2f1c626e authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Merge branch 'QubesOS:main' into overflow-fix

85249f7f7be47ebe877e1d7d26aa43442c989741 authored almost 2 years ago by Yukikoo <[email protected]>
version 4.17.0-3

62bc37d56e72ba3e4957c3eb039090963e7cb147 authored almost 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Work around presumed Intel CPU or iGPU PAT errata

Intel CPUs ignore the high bit in a PAT entry when accessing GPU memory.
With Xen’s PAT, this ca...

b485bc9e415c484538463b287791d048d9059ad4 authored almost 2 years ago by Demi Marie Obenour <[email protected]>
xen backport: prevent overflow with high frequency TSC

requirement to fix https://github.com/QubesOS/qubes-issues/issues/7856

052eb4185bda3b91d5309935a9d26b58f38fe207 authored almost 2 years ago by Neowutran <[email protected]>
Merge remote-tracking branch 'origin/pr/147'

* origin/pr/147:
Relocate the ESRT when booting via multiboot2
Validate EFI memory descriptors

18e1968e91434645d886b81f7c99aa1791f4a63f authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Backport PAT changes from Xen git master

They are prerequisites for subsequent PAT changes that Qubes might also
want to backport, and (u...

725cfc6fef72ce9880e68775ecd414002732a262 authored about 2 years ago by Demi Marie Obenour <[email protected]>
Relocate the ESRT when booting via multiboot2

This was missed in the initial patchset. The patch sent upstream is
larger and involves signifi...

7a5eb600c0f8b3dae436834255040f84c330803b authored about 2 years ago by Demi Marie Obenour <[email protected]>
Validate EFI memory descriptors

It turns out that these can be invalid in various ways. Based on code
Ard Biesheuvel contribute...

dd031c503662a2ce6f16bbb7ad5d962f58d5488c authored about 2 years ago by Demi Marie Obenour <[email protected]>
version 4.17.0-2

5f067f921e5917bd7a3605c5c7e29aaf6d3ed3b6 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
rpm: fix hv_abi variable

2e8b4150e4610237540748bc46ac171110600bd1 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-1

eab78514fd5bae44231fe3dc996e30a47422de94 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.17.0-rc3-1

e572626e9d8d826346a582639c7601a8e2db9408 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
archlinux: make it work for -rc version

023d353f0b633cb76b136037df401048c325ce1c authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
archlinux: update packaging

And refresh patch

6a3bf1842904393b851d368eb6a96fffa2325e2e authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Drop Debian packaging

Use upstream Debian packages directly.

103a570fd677ca6248f3e7c231fe2516024378b0 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Update packaging

- bash-completion filename changed
- make libexec symlink relative
- add new files
- use `@VERSI...

c097f95381bc1748deec357759782691db756260 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Rebase Debian patches to 4.17

115a8c373c7ba6394d1e48662dc136569e17aaa5 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Update config for Xen 4.17

a51887d220f30d29076826d8b69b488f77b43ced authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
rpm: drop qemu stuff

qemu is not necessary in dom0, so don't build it at all.
This includes also dropping xen-qemu-to...

1e25a131f1fa12ee3589143ae725313deafc4428 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Rebase patches on 4.17, make them git-am compatible

94dd4e3d844bf04e0088a6e7f6c8ca1c3d0d724c authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Drop patches not applicable to 4.17 anymore

f1765c715350b5d93e50bbc8f774969b1295492d authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Remove patches not referenced anywhere

d478b36127abeefc3db96f344c39fd388addaa15 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.14.5-14

6ce773288598cc5427fc71f6a9a31da5d30a37e2 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
Backport timers migration fix

QubesOS/qubes-issues#7340

3c18fcf69a1e4c1c49dbef317bd105b01dc287eb authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>
version 4.14.5-13

e5d73801a6fb9f1371de9236728c1e04935dc350 authored about 2 years ago by Marek Marczykowski-Górecki <[email protected]>