Fix for qxl/spice support. Fix for CVE-2011-2212 & CVE-2011-2512. Drop the number...
authorDoug Goldstein <cardoe@gentoo.org>
Thu, 21 Jul 2011 20:52:11 +0000 (20:52 +0000)
committerDoug Goldstein <cardoe@gentoo.org>
Thu, 21 Jul 2011 20:52:11 +0000 (20:52 +0000)
Package-Manager: portage-2.1.10.7/cvs/Linux x86_64

app-emulation/qemu-kvm/ChangeLog
app-emulation/qemu-kvm/Manifest
app-emulation/qemu-kvm/qemu-kvm-0.14.1-r2.ebuild [new file with mode: 0644]

index 22f8e1f2b2f92fd05927d14be4889fc054b3b813..98c5948cc834b3c3bb7efa82215e1b8ae940a75f 100644 (file)
@@ -1,6 +1,13 @@
 # ChangeLog for app-emulation/qemu-kvm
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/app-emulation/qemu-kvm/ChangeLog,v 1.57 2011/06/11 04:29:39 cardoe Exp $
+# $Header: /var/cvsroot/gentoo-x86/app-emulation/qemu-kvm/ChangeLog,v 1.58 2011/07/21 20:52:11 cardoe Exp $
+
+*qemu-kvm-0.14.1-r2 (21 Jul 2011)
+
+  21 Jul 2011; Doug Goldstein <cardoe@gentoo.org> +qemu-kvm-0.14.1-r2.ebuild:
+  Fix for qxl/spice support. Fix for CVE-2011-2212 & CVE-2011-2512. Drop the
+  number of targets we build by default to just the minimal for qemu-kvm. bug
+  #372411, bug #372691
 
   11 Jun 2011; Doug Goldstein <cardoe@gentoo.org> qemu-kvm-0.14.1-r1.ebuild:
   Make USE=vhost-net the default. bug #370939
index a02a21e50d079fd86942656bd91149530268cb99..1900df27fd12e05c4c3e77ab42910064f59ac558 100644 (file)
@@ -5,9 +5,11 @@ AUX qemu-kvm-0.12.3-include-madvise-defines.patch 274 RMD160 2b2b454fabc3b5362c0
 AUX qemu-kvm-guest-hang-on-usb-add.patch 3491 RMD160 7bc186c283b0eb220a47895f7cab50e191f1a3ea SHA1 00f36fd0197fa9d359e28a9ef2f56a1ee860fddf SHA256 d3068a419d69dbe44758830509fc13460d1497b14a5a10ffad910552da0c86b3
 DIST qemu-kvm-0.13.0.tar.gz 5153895 RMD160 7b8f4d8cdbb9730bb9d7fbf4cec165a8703696c4 SHA1 b8cfb8e8dbd403281a98a41f7d3eeaecc0aac8f1 SHA256 6db2600d7e3c1ed12feb6dc7596c23324bc2036a72f101cf580cef252ea9be53
 DIST qemu-kvm-0.14.1-backports-1.tar.bz2 1127 RMD160 7868908c1328cfcbc3e2c60124155f64fb8688e0 SHA1 a4ce58828516b60596c8fea878d6f2cb6bab40d0 SHA256 e636759e1a04aacc49247c1d1eb40d0f2c9e5c642b5404441990f1445483370a
+DIST qemu-kvm-0.14.1-backports-2.tar.bz2 20045 RMD160 a6dfdfc4969ff96d287af389c99c9df9df16ff07 SHA1 4ea70f09ca8d24e30d307319352d9857031d3ccb SHA256 ab0e30b550475b379215d2fdeae9be2b8ad4e66a42bfad406683132892ea5982
 DIST qemu-kvm-0.14.1.tar.gz 5321321 RMD160 e3d69b4756bb0e45d14baad72d85827d949e0ae0 SHA1 7378f10ea04db19e5a5009cae1ecb65517e82877 SHA256 a59c4f6ab8646f2f019d2f9f15443e4db8289cf7cf47743d3c63d18fc584da27
 EBUILD qemu-kvm-0.13.0-r2.ebuild 7933 RMD160 92674548b241a1e698820ab892e145ea9cf10c11 SHA1 d2ab36fb81a4d63a1726ffec53eb83f35a986e0b SHA256 794d92dbcbef069f140051091a17853ddabe11baa1b55bc76bfc7319e7ece635
 EBUILD qemu-kvm-0.14.1-r1.ebuild 8590 RMD160 4e9b4555439ef3850772449c2d3df59a5c12e8cb SHA1 cb1a6ff9ea4306e9920a2906ca693d5275403473 SHA256 9631edfe81af034cd0876a1502ccbe08b1325957c314af02d54c08f6340f7097
+EBUILD qemu-kvm-0.14.1-r2.ebuild 8815 RMD160 b054ffed939f197fd8081147579b6dffc90c02cf SHA1 4a4e0cb41f4cef4a596938fde30d04cf71e5a960 SHA256 aab1be8e246c3db97f13838cf08e86602cca0dd5d8c996316d120641b29ed00e
 EBUILD qemu-kvm-9999.ebuild 8365 RMD160 0b58833811ff033e62ee45b1b5ba2232746e432b SHA1 3eec4fd431bf1dc597714ef39d4205c08aacf077 SHA256 3720954c6247b4aa767b22d9d835313892bfb0792e9a0e22e736c66ca2e5a8fb
-MISC ChangeLog 13102 RMD160 19c7b6ddd8a9da6e97676b75c1861e7e00d718b5 SHA1 ff08bdb1065c373e7d2dd68db1de3ae01b7d1d80 SHA256 a8d73c35e21cb73e37b6e39a72b98cbf7cca788aee5e79df6313ddfa6819e55e
+MISC ChangeLog 13394 RMD160 25f529958b28ec6d7cae26c0ec3648114fab3ed2 SHA1 94ddcf22f3312d5230356f9f09a9ae23fa0542f8 SHA256 98f1d2bb4319ef9bdc0bd257eb3c909e5a3600ded0cc5432fbda31d04ddb5276
 MISC metadata.xml 1492 RMD160 aca7aa5f18297340d955e4f015c521d2fa82ac31 SHA1 2b141c7a4a4dba5eb734dc48537d6b8356320410 SHA256 7a450ebff5eec77efb6b8a209ca44c4e648c37932914ae243b869ef7dbb17c9e
diff --git a/app-emulation/qemu-kvm/qemu-kvm-0.14.1-r2.ebuild b/app-emulation/qemu-kvm/qemu-kvm-0.14.1-r2.ebuild
new file mode 100644 (file)
index 0000000..4a167ca
--- /dev/null
@@ -0,0 +1,276 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/app-emulation/qemu-kvm/qemu-kvm-0.14.1-r2.ebuild,v 1.1 2011/07/21 20:52:11 cardoe Exp $
+
+BACKPORTS=2
+
+EAPI="2"
+
+if [[ ${PV} = *9999* ]]; then
+       EGIT_REPO_URI="git://git.kernel.org/pub/scm/virt/kvm/qemu-kvm.git"
+       GIT_ECLASS="git"
+fi
+
+inherit eutils flag-o-matic ${GIT_ECLASS} linux-info toolchain-funcs multilib
+
+if [[ ${PV} = *9999* ]]; then
+       SRC_URI=""
+       KEYWORDS=""
+else
+       SRC_URI="mirror://sourceforge/kvm/${PN}/${P}.tar.gz
+       ${BACKPORTS:+http://dev.gentoo.org/~cardoe/distfiles/${P}-backports-${BACKPORTS}.tar.bz2}"
+       KEYWORDS="~amd64 ~ppc ~ppc64 ~x86"
+fi
+
+DESCRIPTION="QEMU + Kernel-based Virtual Machine userland tools"
+HOMEPAGE="http://www.linux-kvm.org"
+
+LICENSE="GPL-2"
+SLOT="0"
+# xen is disabled until the deps are fixed
+IUSE="+aio alsa bluetooth brltty curl debug esd fdt hardened jpeg ncurses \
+png pulseaudio qemu-ifup rbd sasl sdl spice ssl threads vde \
++vhost-net xen"
+# static, depends on libsdl being built with USE=static-libs, which can not
+# be expressed in current EAPI's
+
+COMMON_TARGETS="arm cris m68k microblaze mips mipsel ppc ppc64 sh4 sh4eb sparc sparc64"
+IUSE_SOFTMMU_TARGETS="${COMMON_TARGETS} mips64 mips64el ppcemb"
+IUSE_USER_TARGETS="${COMMON_TARGETS} i386 x86_64 alpha armeb ppc64abi32 sparc32plus"
+
+# Setup the default SoftMMU targets, while using the loops
+# below to setup the other targets. i386 & x86_64 should be the only
+# defaults on for qemu-kvm
+IUSE="${IUSE} +qemu_softmmu_targets_i386 +qemu_softmmu_targets_x86_64"
+
+for target in ${IUSE_SOFTMMU_TARGETS}; do
+       IUSE="${IUSE} qemu_softmmu_targets_${target}"
+done
+
+for target in ${IUSE_USER_TARGETS}; do
+       IUSE="${IUSE} qemu_user_targets_${target}"
+done
+
+RESTRICT="test"
+
+RDEPEND="
+       !app-emulation/kqemu
+       !app-emulation/qemu
+       !app-emulation/qemu-softmmu
+       !app-emulation/qemu-user
+       !app-emulation/qemu-kvm-spice
+       sys-apps/pciutils
+       >=sys-apps/util-linux-2.16.0
+       sys-libs/zlib
+       aio? ( dev-libs/libaio )
+       alsa? ( >=media-libs/alsa-lib-1.0.13 )
+       bluetooth? ( net-wireless/bluez )
+       brltty? ( app-accessibility/brltty )
+       curl? ( net-misc/curl )
+       esd? ( media-sound/esound )
+       fdt? ( >=sys-apps/dtc-1.2.0 )
+       jpeg? ( virtual/jpeg )
+       ncurses? ( sys-libs/ncurses )
+       png? ( media-libs/libpng )
+       pulseaudio? ( media-sound/pulseaudio )
+       qemu-ifup? ( sys-apps/iproute2 net-misc/bridge-utils )
+       rbd? ( sys-cluster/ceph )
+       sasl? ( dev-libs/cyrus-sasl )
+       sdl? ( >=media-libs/libsdl-1.2.11[X] )
+       spice? ( app-emulation/spice )
+       ssl? ( net-libs/gnutls )
+       vde? ( net-misc/vde )
+       xen? ( app-emulation/xen )
+"
+
+DEPEND="${RDEPEND}
+       app-text/texi2html
+       >=sys-kernel/linux-headers-2.6.35
+       ssl? ( dev-util/pkgconfig )
+"
+
+kvm_kern_warn() {
+       eerror "Please enable KVM support in your kernel, found at:"
+       eerror
+       eerror "  Virtualization"
+       eerror "    Kernel-based Virtual Machine (KVM) support"
+       eerror
+}
+
+pkg_setup() {
+       use qemu_softmmu_targets_x86_64 || ewarn "You disabled default target QEMU_SOFTMMU_TARGETS=x86_64"
+
+       if kernel_is lt 2 6 25; then
+               eerror "This version of KVM requres a host kernel of 2.6.25 or higher."
+               eerror "Either upgrade your kernel"
+       else
+               if ! linux_config_exists; then
+                       eerror "Unable to check your kernel for KVM support"
+                       kvm_kern_warn
+               elif ! linux_chkconfig_present KVM; then
+                       kvm_kern_warn
+               fi
+               if use vhost-net && ! linux_chkconfig_present VHOST_NET ; then
+                       ewarn "You have to enable CONFIG_VHOST_NET in the kernel"
+                       ewarn "to have vhost-net support."
+               fi
+       fi
+
+       enewgroup kvm
+}
+
+src_prepare() {
+       # prevent docs to get automatically installed
+       sed -i '/$(DESTDIR)$(docdir)/d' Makefile || die
+       # Alter target makefiles to accept CFLAGS set via flag-o
+       sed -i 's/^\(C\|OP_C\|HELPER_C\)FLAGS=/\1FLAGS+=/' \
+               Makefile Makefile.target || die
+       # append CFLAGS while linking
+       sed -i 's/$(LDFLAGS)/$(QEMU_CFLAGS) $(CFLAGS) $(LDFLAGS)/' rules.mak || die
+
+       # remove part to make udev happy
+       sed -e 's~NAME="%k", ~~' -i kvm/scripts/65-kvm.rules || die
+
+       # ${PN}-guest-hang-on-usb-add.patch was sent by Timothy Jones
+       # to the qemu-devel ml - bug 337988
+       epatch "${FILESDIR}/qemu-0.11.0-mips64-user-fix.patch"
+
+       [[ -n ${BACKPORTS} ]] && \
+               EPATCH_FORCE=yes EPATCH_SUFFIX="patch" EPATCH_SOURCE="${S}/patches" \
+                       epatch
+}
+
+src_configure() {
+       local conf_opts audio_opts user_targets
+
+       for target in ${IUSE_SOFTMMU_TARGETS} ; do
+               use "qemu_softmmu_targets_${target}" && \
+               softmmu_targets="${softmmu_targets} ${target}-softmmu"
+       done
+
+       for target in ${IUSE_USER_TARGETS} ; do
+               use "qemu_user_targets_${target}" && \
+               user_targets="${user_targets} ${target}-linux-user"
+       done
+
+       if [ -z "${softmmu_targets}" ]; then
+               conf_opts="${conf_opts} --disable-system"
+       else
+               einfo "Building the following softmmu targets: ${softmmu_targets}"
+       fi
+
+       if [ ! -z "${user_targets}" ]; then
+               einfo "Building the following user targets: ${user_targets}"
+               conf_opts="${conf_opts} --enable-linux-user"
+       else
+               conf_opts="${conf_opts} --disable-linux-user"
+       fi
+
+       # Fix QA issues. QEMU needs executable heaps and we need to mark it as such
+       conf_opts="${conf_opts} --extra-ldflags=-Wl,-z,execheap"
+
+       # Add support for static builds
+       #use static && conf_opts="${conf_opts} --static"
+
+       # Support debug USE flag
+       use debug && conf_opts="${conf_opts} --enable-debug --disable-strip"
+
+       # Fix the $(prefix)/etc issue
+       conf_opts="${conf_opts} --sysconfdir=/etc"
+
+       #config options
+       conf_opts="${conf_opts} $(use_enable aio linux-aio)"
+       conf_opts="${conf_opts} $(use_enable bluetooth bluez)"
+       conf_opts="${conf_opts} $(use_enable brltty brlapi)"
+       conf_opts="${conf_opts} $(use_enable curl)"
+       conf_opts="${conf_opts} $(use_enable fdt)"
+       conf_opts="${conf_opts} $(use_enable hardened user-pie)"
+       conf_opts="${conf_opts} $(use_enable jpeg vnc-jpeg)"
+       conf_opts="${conf_opts} $(use_enable ncurses curses)"
+       conf_opts="${conf_opts} $(use_enable png vnc-png)"
+       conf_opts="${conf_opts} $(use_enable rbd)"
+       conf_opts="${conf_opts} $(use_enable sasl vnc-sasl)"
+       conf_opts="${conf_opts} $(use_enable sdl)"
+       conf_opts="${conf_opts} $(use_enable spice)"
+       conf_opts="${conf_opts} $(use_enable ssl vnc-tls)"
+       conf_opts="${conf_opts} $(use_enable threads vnc-thread)"
+       conf_opts="${conf_opts} $(use_enable vde)"
+       conf_opts="${conf_opts} $(use_enable vhost-net)"
+       conf_opts="${conf_opts} $(use_enable xen)"
+       conf_opts="${conf_opts} --disable-darwin-user --disable-bsd-user"
+
+       # audio options
+       audio_opts="oss"
+       use alsa && audio_opts="alsa ${audio_opts}"
+       use esd && audio_opts="esd ${audio_opts}"
+       use pulseaudio && audio_opts="pa ${audio_opts}"
+       use sdl && audio_opts="sdl ${audio_opts}"
+       ./configure --prefix=/usr \
+               --disable-strip \
+               --disable-werror \
+               --enable-kvm \
+               --enable-nptl \
+               --enable-uuid \
+               ${conf_opts} \
+               --audio-drv-list="${audio_opts}" \
+               --target-list="${softmmu_targets} ${user_targets}" \
+               --cc="$(tc-getCC)" \
+               --host-cc="$(tc-getBUILD_CC)" \
+               || die "configure failed"
+
+               # this is for qemu upstream's threaded support which is
+               # in development and broken
+               # the kvm project has its own support for threaded IO
+               # which is always on and works
+               # --enable-io-thread \
+}
+
+src_install() {
+       emake DESTDIR="${D}" install || die "make install failed"
+
+       if [ ! -z "${softmmu_targets}" ]; then
+               insinto /$(get_libdir)/udev/rules.d/
+               doins kvm/scripts/65-kvm.rules || die
+
+               if use qemu-ifup; then
+                       insinto /etc/qemu/
+                       insopts -m0755
+                       doins kvm/scripts/qemu-ifup || die
+               fi
+
+               if use qemu_softmmu_targets_x86_64 ; then
+                       dobin "${FILESDIR}"/qemu-kvm
+                       dosym /usr/bin/qemu-kvm /usr/bin/kvm
+               else
+                       elog "You disabled QEMU_SOFTMMU_TARGETS=x86_64, this disables install"
+                       elog "of /usr/bin/qemu-kvm and /usr/bin/kvm"
+               fi
+       fi
+
+       dodoc Changelog MAINTAINERS TODO pci-ids.txt || die
+       newdoc pc-bios/README README.pc-bios || die
+       dohtml qemu-doc.html qemu-tech.html || die
+}
+
+pkg_postinst() {
+
+       if [ ! -z "${softmmu_targets}" ]; then
+               elog "If you don't have kvm compiled into the kernel, make sure you have"
+               elog "the kernel module loaded before running kvm. The easiest way to"
+               elog "ensure that the kernel module is loaded is to load it on boot."
+               elog "For AMD CPUs the module is called 'kvm-amd'"
+               elog "For Intel CPUs the module is called 'kvm-intel'"
+               elog "Please review /etc/conf.d/modules for how to load these"
+               elog
+               elog "Make sure your user is in the 'kvm' group"
+               elog "Just run 'gpasswd -a <USER> kvm', then have <USER> re-login."
+               elog
+               elog "You will need the Universal TUN/TAP driver compiled into your"
+               elog "kernel or loaded as a module to use the virtual network device"
+               elog "if using -net tap.  You will also need support for 802.1d"
+               elog "Ethernet Bridging and a configured bridge if using the provided"
+               elog "kvm-ifup script from /etc/kvm."
+               elog
+               elog "The gnutls use flag was renamed to ssl, so adjust your use flags."
+       fi
+}