jammy/linux-gcp: 5.15.0-1029.36 -proposed tracker

Bug #2003429 reported by Stefan Bader
20
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Kernel SRU Workflow
Fix Released
Medium
Unassigned
Automated-testing
Fix Released
Medium
Canonical Kernel Team
Boot-testing
Fix Released
Medium
Unassigned
Certification-testing
Invalid
Medium
Unassigned
Kernel-signoff
Fix Released
Undecided
Dimitri John Ledkov
New-review
Fix Released
Medium
Andy Whitcroft
Prepare-package
Fix Released
Medium
Luke Nowakowski-Krijger
Prepare-package-generate
Fix Released
Undecided
Unassigned
Prepare-package-lrg
Fix Released
Medium
Luke Nowakowski-Krijger
Prepare-package-lrm
Fix Released
Medium
Luke Nowakowski-Krijger
Prepare-package-lrs
Fix Released
Medium
Luke Nowakowski-Krijger
Prepare-package-meta
Fix Released
Medium
Luke Nowakowski-Krijger
Prepare-package-signed
Fix Released
Medium
Luke Nowakowski-Krijger
Promote-signing-to-proposed
Invalid
Medium
Unassigned
Promote-to-proposed
Fix Released
Medium
Ubuntu Stable Release Updates Team
Promote-to-security
Fix Released
Medium
Andy Whitcroft
Promote-to-updates
Fix Released
Medium
Andy Whitcroft
Regression-testing
Fix Released
Medium
Canonical Kernel Team
Security-signoff
Fix Released
Medium
Steve Beattie
Sru-review
Fix Released
Medium
Andy Whitcroft
Verification-testing
Fix Released
Medium
Canonical Kernel Team
canonical-signing-jobs
Fix Released
Medium
Andy Whitcroft
linux-gcp (Ubuntu)
Jammy
Fix Released
Medium
Unassigned

Bug Description

This bug will contain status and test results related to a kernel source (or snap) as stated in the title.

For an explanation of the tasks and the associated workflow see:
  https://wiki.ubuntu.com/Kernel/kernel-sru-workflow

-- swm properties --
built:
  from: 3108e4b0e9305088
  route-entry: 1
delta:
  promote-to-proposed: [meta, main, lrs, lrm, signed, lrg, generate]
  promote-to-security: []
  promote-to-updates: [lrm, lrs, main, meta, signed]
flag:
  boot-testing-requested: true
  bugs-spammed: true
  proposed-announcement-sent: true
  proposed-testing-requested: true
  stream-from-cycle: true
issue: KSRU-6274
kernel-stable-master-bug: 2003450
packages:
  generate: linux-generate-gcp
  lrg: linux-restricted-generate-gcp
  lrm: linux-restricted-modules-gcp
  lrs: linux-restricted-signatures-gcp
  main: linux-gcp
  meta: linux-meta-gcp
  signed: linux-signed-gcp
phase: Complete
phase-changed: Wednesday, 15. February 2023 09:46 UTC
reason: {}
synthetic:
  :promote-to-as-proposed: Fix Released
trackers:
  focal/linux-gcp-5.15: bug 2003490
variant: debs
versions:
  lrm: 5.15.0-1029.36
  main: 5.15.0-1029.36
  meta: 5.15.0.1029.24
  signed: 5.15.0-1029.36
~~:
  clamps:
    new-review: 3108e4b0e9305088
    promote-to-proposed: 3108e4b0e9305088
    self: 5.15.0-1029.36
    sru-review: 3108e4b0e9305088

CVE References

Stefan Bader (smb)
tags: added: kernel-release-tracking-bug-live
description: updated
tags: added: kernel-sru-cycle-2023.01.02-2
description: updated
description: updated
tags: added: kernel-sru-derivative-of-2003450
Changed in kernel-sru-workflow:
status: New → Confirmed
importance: Undecided → Medium
Changed in linux-gcp (Ubuntu Jammy):
importance: Undecided → Medium
Changed in kernel-sru-workflow:
status: Confirmed → Triaged
description: updated
Changed in kernel-sru-workflow:
status: Triaged → In Progress
tags: added: kernel-jira-issue-ksru-6274
description: updated
description: updated
description: updated
summary: - jammy/linux-gcp: <version to be filled> -proposed tracker
+ jammy/linux-gcp: 5.15.0-1029.36 -proposed tracker
description: updated
Andy Whitcroft (apw)
description: updated
description: updated
description: updated
Andy Whitcroft (apw)
tags: added: kernel-signing-bot
Changed in canonical-signing-jobs:
assignee: nobody → Andy Whitcroft (apw)
importance: Undecided → Medium
importance explanation: unset → unset
status explanation: unset → validate \ --exclude jammy:linux-gcp --publications \ ~canonical-kernel-team/+archive/ubuntu/ppa/+sourcepub/14455875 \ ~canonical-kernel-team/+archive/ubuntu/ppa/+sourcepub/14455876 \ ~canonical-kernel-team/+archive/ubuntu/ppa/+sourcepub/14456023 \ ~canonical-kernel-team/+archive/ubuntu/ppa/+sourcepub/14455877 \ ~canonical-kernel-team/+archive/ubuntu/ppa/+sourcepub/14455878 \ ~canonical-kernel-team/+archive/ubuntu/ppa-ps/+sourcepub/14455891 \ ~canonical-kernel-team/+archive/ubuntu/ppa-ps/+sourcepub/14455892 copy \ --from ppa:canonical-kernel-team/ubuntu/ppa --from-suite jammy --sources \ linux-gcp/5.15.0-1029.36 \ linux-meta-gcp/5.15.0.1029.24 \ linux-generate-gcp/5.15.0-1029.36 \ linux-signed-gcp/5.15.0-1029.36/signing \ linux-restricted-modules-gcp/5.15.0-1029.36 \ --from ppa:canonical-kernel-team/ubuntu/ppa-ps --from-suite jammy --sources \ linux-restricted-generate-gcp/5.15.0-1029.36 \ linux-restricted-signatures-gcp/5.15.0-1029.36/signing \ --to signing:ubuntu/4 --to-suite jammy copy \ --from signing:ubuntu/4 --from-suite jammy --sources \ linux-gcp/5.15.0-1029.36 \ linux-meta-gcp/5.15.0.1029.24 \ linux-signed-gcp/5.15.0-1029.36 \ linux-restricted-modules-gcp/5.15.0-1029.36 \ linux-restricted-signatures-gcp/5.15.0-1029.36 \ --to ppa:canonical-kernel-security-team/ubuntu/proposed3 --to-suite jammy delete \ --from signing:ubuntu/4 --from-suite jammy --sources \ linux-gcp/5.15.0-1029.36 \ linux-meta-gcp/5.15.0.1029.24 \ linux-generate-gcp/5.15.0-1029.36 \ linux-signed-gcp/5.15.0-1029.36 \ linux-restricted-modules-gcp/5.15.0-1029.36 \ linux-restricted-generate-gcp/5.15.0-1029.36 \ linux-restricted-signatures-gcp/5.15.0-1029.36
status: New → Triaged
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in linux-gcp (Ubuntu Jammy):
status: New → Confirmed
description: updated
Changed in canonical-signing-jobs:
status: Triaged → Confirmed
description: updated
Andy Whitcroft (apw)
Changed in canonical-signing-jobs:
status: Confirmed → In Progress
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Andy Whitcroft (apw)
Changed in canonical-signing-jobs:
importance explanation: unset → Successful
status: In Progress → Fix Released
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
tags: added: automated-testing-passed
tags: added: regression-testing-passed
description: updated
Revision history for this message
Luke Nowakowski-Krijger (lukenow) wrote :

The only verification needed on this kernel is the sev-snp enablement but it seems Microsoft tested so marking verification testing passed. rest of ADT/RT look good.

tags: added: verification-testing-passed
description: updated
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (61.1 KiB)

This bug was fixed in the package linux-gcp - 5.15.0-1029.36

---------------
linux-gcp (5.15.0-1029.36) jammy; urgency=medium

  * jammy/linux-gcp: 5.15.0-1029.36 -proposed tracker (LP: #2003429)

  [ Ubuntu: 5.15.0-60.66 ]

  * jammy/linux: 5.15.0-60.66 -proposed tracker (LP: #2003450)
  * Revoke & rotate to new signing key (LP: #2002812)
    - [Packaging] Revoke and rotate to new signing key

linux-gcp (5.15.0-1028.35) jammy; urgency=medium

  * jammy/linux-gcp: 5.15.0-1028.35 -proposed tracker (LP: #2001767)

  * Add support for SEV-SNP (LP: #2001605)
    - KVM: SVM: Define sev_features and vmpl field in the VMSA
    - KVM: SEV: Refactor out sev_es_state struct
    - KVM: SVM: Create a separate mapping for the SEV-ES save area
    - KVM: SVM: Create a separate mapping for the GHCB save area
    - KVM: SVM: Update the SEV-ES save area mapping
    - x86/boot: Introduce helpers for MSR reads/writes
    - x86/boot: Use MSR read/write helpers instead of inline assembly
    - SAUCE: x86/compressed/64: Detect/setup SEV/SME features earlier in boot
    - x86/sev: Detect/setup SEV/SME features earlier in boot
    - x86/sev: Use CC_ATTR attribute to generalize string I/O unroll
    - x86/mm: Extend cc_attr to include AMD SEV-SNP
    - x86/sev: Shorten GHCB terminate macro names
    - SAUCE: x86/sev: Define the Linux specific guest termination reasons
    - x86/sev: Save the negotiated GHCB version
    - x86/sev: Carve out HV call's return value verification
    - x86/sev: Expose sev_es_ghcb_hv_call() for use by HyperV
    - x86/sev: Check SEV-SNP features support
    - x86/sev: Add a helper for the PVALIDATE instruction
    - x86/sev: Check the vmpl level
    - x86/compressed: Add helper for validating pages in the decompression stage
    - x86/compressed: Register GHCB memory when SEV-SNP is active
    - x86/sev: Register GHCB memory when SEV-SNP is active
    - x86/sev: Rename mem_encrypt.c to mem_encrypt_amd.c
    - x86/sev: Add helper for validating pages in early enc attribute changes
    - treewide: Replace the use of mem_encrypt_active() with cc_platform_has()
    - x86/head64: Carve out the guest encryption postprocessing into a helper
    - SAUCE: x86/kernel: Make the .bss..decrypted section shared in RMP table
    - x86/kernel: Validate ROM memory before accessing when SEV-SNP is active
    - SAUCE: x86/mm: Add support to validate memory when changing C-bit
    - x86/sev: Remove do_early_exception() forward declarations
    - x86/sev: Use SEV-SNP AP creation to start secondary CPUs
    - x86/head/64: Re-enable stack protection
    - x86/compressed/acpi: Move EFI detection to helper
    - x86/compressed/acpi: Move EFI system table lookup to helper
    - x86/compressed/acpi: Move EFI config table lookup to helper
    - x86/compressed/acpi: Move EFI vendor table lookup to helper
    - x86/compressed/acpi: Move EFI kexec handling into common code
    - x86/boot: Add Confidential Computing type to setup_data
    - KVM: x86: Move lookup of indexed CPUID leafs to helper
    - x86/sev: Move MSR-based VMGEXITs for CPUID to helper
    - x86/compressed/64: Add support for SEV-SNP CPUID table in #VC handlers
    - x86/boot: Add a pointer to Confident...

Changed in linux-gcp (Ubuntu Jammy):
status: Confirmed → Fix Released
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Workflow done!

All tasks have been completed and the bug is being closed

Changed in kernel-sru-workflow:
status: In Progress → Fix Committed
Changed in kernel-sru-workflow:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.