From ef8b8e5a456c9b00e5856ca0dbc9ab9d0a91e81b Mon Sep 17 00:00:00 2001 From: Fernando Rodrigues Date: Sun, 12 Jan 2025 21:23:27 +0000 Subject: [PATCH 1/3] xen: 4.19.1 -> 4.20.0 Includes patches for XSA #469. (Training Solo) Signed-off-by: Fernando Rodrigues --- pkgs/by-name/xe/xen/package.nix | 38 +++++++++++++-------------------- 1 file changed, 15 insertions(+), 23 deletions(-) diff --git a/pkgs/by-name/xe/xen/package.nix b/pkgs/by-name/xe/xen/package.nix index e5fffebe293b..b0df72e7f9e6 100644 --- a/pkgs/by-name/xe/xen/package.nix +++ b/pkgs/by-name/xe/xen/package.nix @@ -6,45 +6,37 @@ buildXenPackage.override { inherit python3Packages; } { pname = "xen"; - version = "4.19.1"; + version = "4.20.0"; patches = [ (fetchpatch { - url = "https://lore.kernel.org/xen-devel/e2caa6648a0b6c429349a9826d8fbc4338222482.1733766758.git.andrii.sultanov@cloud.com/raw"; - hash = "sha256-JC1ueXuC1Jdi2gtUsjOHmTeEx56zjotMMLde5vBonxc="; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-01.patch"; + hash = "sha256-go743oBhYDuxsK0Xc6nK/WxutQQwc2ERtLKhCU9Dnng="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa467.patch"; - hash = "sha256-O2IwfRo6BnXAO04xjKmOyrV6J6Q1mAVLHWNCxqIEQGU="; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-02.patch"; + hash = "sha256-FTtEGAPFYxsun38hLhVMKJ1TFJOsTMK3WWPkO0R/OHg=sha256-FTtEGAPFYxsun38hLhVMKJ1TFJOsTMK3WWPkO0R/OHg="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-01.patch"; - hash = "sha256-YUcp9QI49RM/7WCxYzpzppv+vKtyl/NvLy6rIX5hVMw="; - }) - (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-02.patch"; - hash = "sha256-FTtEGAPFYxsun38hLhVMKJ1TFJOsTMK3WWPkO0R/OHg="; - }) - (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-03.patch"; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-03.patch"; hash = "sha256-UkYMSpUgFvr4GJPXLgQsCyppGkNbeiFMyCZORK5tfmA="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-04.patch"; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-04.patch"; hash = "sha256-lpiDPSHi+v2VfaWE9kp4+hveZKTzojD1F+RHsOtKE3A="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-05.patch"; - hash = "sha256-EKo9a5STX0mTRopoThe3+6gCWat+3XbguLr9QgMheZs="; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-05.patch"; + hash = "sha256-N+WR8S5w9dLISlOhMI71TOH8jvCgVAR8xm310k3ZA/M="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-06.patch"; - hash = "sha256-HU+4apyTZNIFZ9cySOEtNh0JBJDG3LjDLwMvQYq0src="; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-06.patch"; + hash = "sha256-ePuyB3VP9NfQbW36BP3jjMMHKJWFJGeTYUYZqy+IlHQ="; }) (fetchpatch { - url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.19-07.patch"; - hash = "sha256-9S85nkQ9Nn0cMzyRe4KGrFUaLggVxXBeKhoFF4R0y78="; + url = "https://xenbits.xenproject.org/xsa/xsa469/xsa469-4.20-07.patch"; + hash = "sha256-+BsCJa01R2lrbu7tEluGrYSAqu2jJcrpFNUoLMY466c="; }) ]; - rev = "ccf400846780289ae779c62ef0c94757ff43bb60"; - hash = "sha256-s0eCBCd6ybl+kLtXCC6E1sk++w7txXn/B/Cg5acQFfY="; + rev = "3ad5d648cda5add395f49fc3704b2552aae734f7"; + hash = "sha256-v2DRJv+1bym8zAgU74lo1HQ/9rUcyK3qc4Eec4RpcEY="; } From e3c735ccd8febea57e8260157a58a6d1ef9a34b4 Mon Sep 17 00:00:00 2001 From: Fernando Rodrigues Date: Wed, 26 Mar 2025 08:11:13 -0300 Subject: [PATCH 2/3] xen: delete outdated README The README no longer contained any useful information as of Xen 4.20. Signed-off-by: Fernando Rodrigues --- pkgs/by-name/xe/xen/README.md | 133 ---------------------------------- 1 file changed, 133 deletions(-) delete mode 100644 pkgs/by-name/xe/xen/README.md diff --git a/pkgs/by-name/xe/xen/README.md b/pkgs/by-name/xe/xen/README.md deleted file mode 100644 index df3b71b3c956..000000000000 --- a/pkgs/by-name/xe/xen/README.md +++ /dev/null @@ -1,133 +0,0 @@ -

- - - - - Xen Project Logo - - -

- -# Xen Project Hypervisor Xen Fu Panda - -This directory begins the [Xen Project Hypervisor](https://xenproject.org/) build process. - -Some other notable packages that compose the Xen Project Ecosystem include: - -- `ocamlPackages.xenstore`: Mirage's `oxenstore` implementation. -- `ocamlPackages.vchan`: Mirage's `xen-vchan` implementation. -- `ocamlPackages.xenstore-tool`: XAPI's `oxenstore` utilities. -- `xen-guest-agent`: Guest drivers for UNIX domUs. -- `win-pvdrivers`: Guest drivers for Windows domUs. -- `xtf`: The Xen Test Framework. - -## Updating - -### Manually - -1. [Update](https://xenbits.xenproject.org/gitweb/) the `package.nix` file for - the latest branch of Xen. - - Do not forget to set the `branch`, `version`, and `latest` attributes. - - The revisions are preferably commit hashes, but tag names are acceptable - as well. -1. Make sure it builds. -1. Use the NixOS module to test if dom0 boots successfully on the new version. -1. Make sure the `meta` attributes evaluate to something that makes sense. The - following one-line command is useful for testing this: - - ```console - echo -e "\033[1m$(nix eval .#xen.meta.description --raw 2> /dev/null)\033[0m\n\n$(nix eval .#xen.meta.longDescription --raw 2> /dev/null)" - ``` - -1. Run `xtf --all --host` as root when booted into the Xen update, and make - sure no important tests fail. -1. Clean up your changes and commit them, making sure to follow the - [Nixpkgs Contribution Guidelines](../../../../CONTRIBUTING.md). -1. Open a PR and await a review from the current maintainers. - -## Features - -### Generic Builder - -`buildXenPackage` is a helpful utility capable of building Xen when passed -certain attributes. The `package.nix` file on this directory includes all -important attributes for building a Xen package with Nix. Downstreams can -pin their Xen revision or include extra patches if the default Xen package -does not meet their needs. - -### EFI - -Building `xen.efi` requires an `ld` with PE support.[^2] - -We use a `makeFlag` to override the `$LD` environment variable to point to our -patched `efiBinutils`. For more information, see the comment in `pkgs/build-support/xen/default.nix`. - -> [!TIP] -> If you are certain you will not be running Xen in an x86 EFI environment, disable -the `withEFI` flag with an [override](https://nixos.org/manual/nixpkgs/stable/#chap-overrides) -to save you the need to compile `efiBinutils`. - -## Security - -We aim to support the **latest** version of Xen at any given time. -See the [Xen Support Matrix](https://xenbits.xen.org/docs/unstable/support-matrix.html) -for a list of versions. As soon as a version is no longer the newest, it should -be removed from Nixpkgs (`master`). If you need earlier versions of Xen, consider -building your own Xen by following the instructions in the **Generic Builder** -section. - -> [!CAUTION] -> Pull requests that introduce XSA patches -should have the `1.severity: security` label. - -### Maintainers - -Xen is a particularly complex piece of software, so we are always looking for new -maintainers. Help out by [making and triaging issues](https://github.com/NixOS/nixpkgs/issues/new/choose), -[sending build fixes and improvements through PRs](https://github.com/NixOS/nixpkgs/compare), -updating the branches, and [patching security flaws](https://xenbits.xenproject.org/xsa/). - -We are also looking for testers, particularly those who can test Xen on AArch64 -machines. Open issues for any build failures or runtime errors you find! - -## Tests - -So far, we only have had one simple automated test that checks for -the correct `pkg-config` output files. - -Due to Xen's nature as a type-1 hypervisor, it is not a trivial matter to design -new tests, as even basic functionality requires a machine booted in a dom0 -kernel. For this reason, most testing done with this package must be done -manually in a NixOS machine with `virtualisation.xen.enable` set to `true`. - -Another unfortunate thing is that none of the Xen commands have a `--version` -flag. This means that `testers.testVersion` cannot ascertain the Xen version. -The only way to verify that you have indeed built the correct version is to -boot into the freshly built Xen kernel and run `xl info`. - -

- - Xen Fu Panda - -

- -[^1]: We also produce fake `git`, `wget` and `hostname` binaries that do nothing, - to prevent the build from failing because Xen cannot fetch the sources that - were already fetched by Nix. -[^2]: From the [Xen Documentation](https://xenbits.xenproject.org/docs/unstable/misc/efi.html): - > For x86, building `xen.efi` requires `gcc` 4.5.x or above (4.6.x or newer - recommended, as 4.5.x was probably never really tested for this purpose) - and `binutils` 2.22 or newer. Additionally, the `binutils` build must be - configured to include support for the x86_64-pep emulation (i.e. - `--enable-targets=x86_64-pep` or an option of equivalent effect should be - passed to the configure script). From 4a0180f434d7378fdce98fabc08f9fbf010c521e Mon Sep 17 00:00:00 2001 From: Fernando Rodrigues Date: Wed, 26 Mar 2025 11:42:48 -0300 Subject: [PATCH 3/3] nixos/xen: dehardcode the .pad section from the UKI builder Upstream, intentionally or not, no longer appends the EFI image with a .pad section for us to hook the rest of the UKI to. This simply dehardcodes .pad from the awk script, instead using the very last section in the binary. (Currently .reloc) Co-authored-by: Yaroslav Bolyukin Signed-off-by: Fernando Rodrigues --- nixos/modules/virtualisation/xen-boot-builder.sh | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/nixos/modules/virtualisation/xen-boot-builder.sh b/nixos/modules/virtualisation/xen-boot-builder.sh index 1b7c1470f6eb..f8363b337662 100755 --- a/nixos/modules/virtualisation/xen-boot-builder.sh +++ b/nixos/modules/virtualisation/xen-boot-builder.sh @@ -1,6 +1,8 @@ # This script is called by ./xen-dom0.nix to create the Xen boot entries. # shellcheck shell=bash +export LC_ALL=C + # Handle input argument and exit if the flag is invalid. See virtualisation.xen.efi.bootBuilderVerbosity below. [[ $# -ne 1 ]] && echo -e "\e[1;31merror:\e[0m xenBootBuilder must be called with exactly one verbosity argument. See the \e[1;34mvirtualisation.xen.efi.bootBuilderVerbosity\e[0m option." && exit 1 case "$1" in @@ -89,7 +91,8 @@ EOF # https://xenbits.xenproject.org/docs/unstable/misc/efi.html. [ "$1" = "debug" ] && echo -e "\e[1;34mxenBootBuilder:\e[0m making Xen UKI..." xenEfi=$(jq -re '."org.xenproject.bootspec.v1".xen' "$bootspecFile") - padding=$(objdump --header --section=".pad" "$xenEfi" | awk '/\.pad/ { printf("0x%016x\n", strtonum("0x"$3) + strtonum("0x"$4))};') + finalSection=$(objdump --header --wide "$xenEfi" | tail -n +6 | sort --key="4,4" | tail -n 1 | grep -Eo '\.[a-z]*') + padding=$(objdump --header --section="$finalSection" "$xenEfi" | awk -v section="$finalSection" '$0 ~ section { printf("0x%016x\n", and(strtonum("0x"$3) + strtonum("0x"$4) + 0xfff, compl(0xfff)))};') [ "$1" = "debug" ] && echo " - padding: $padding" objcopy \ --add-section .config="$tmpCfg" \