Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

virtualbox: 7.0.20 -> 7.0.22 #350707

Merged
merged 1 commit into from
Oct 25, 2024
Merged

virtualbox: 7.0.20 -> 7.0.22 #350707

merged 1 commit into from
Oct 25, 2024

Conversation

LeSuisse
Copy link
Contributor

@LeSuisse LeSuisse commented Oct 23, 2024

Fixes CVE-2024-21248, CVE-2024-21253, CVE-2024-21259, CVE-2024-21263 and CVE-2024-21273.

Changelog:
https://www.virtualbox.org/wiki/Changelog-7.0#v22

Things done

  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 24.11 Release Notes (or backporting 23.11 and 24.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md.

nixpkgs-review result

Generated using nixpkgs-review.

Command: nixpkgs-review pr 350707


x86_64-linux

⏩ 2 packages marked as broken and skipped:
  • linuxKernel.packages.linux_5_4_hardened.virtualbox
  • linuxKernel.packages.linux_5_4_hardened.virtualboxGuestAdditions
❌ 7 packages failed to build:
  • linuxKernel.packages.linux_5_15_hardened.virtualbox
  • linuxKernel.packages.linux_5_15_hardened.virtualboxGuestAdditions
  • linuxKernel.packages.linux_6_1_hardened.virtualbox
  • linuxKernel.packages.linux_6_1_hardened.virtualboxGuestAdditions
  • linuxKernel.packages.linux_hardened.virtualbox (linuxKernel.packages.linux_6_6_hardened.virtualbox)
  • linuxKernel.packages.linux_hardened.virtualboxGuestAdditions (linuxKernel.packages.linux_6_6_hardened.virtualboxGuestAdditions)
  • virtualboxKvm
✅ 37 packages built:
  • linuxKernel.packages.linux_5_10.virtualbox
  • linuxKernel.packages.linux_5_10.virtualboxGuestAdditions
  • linuxKernel.packages.linux_5_10_hardened.virtualbox
  • linuxKernel.packages.linux_5_10_hardened.virtualboxGuestAdditions
  • linuxKernel.packages.linux_5_15.virtualbox
  • linuxKernel.packages.linux_5_15.virtualboxGuestAdditions
  • linuxKernel.packages.linux_5_4.virtualbox
  • linuxKernel.packages.linux_5_4.virtualboxGuestAdditions
  • linuxKernel.packages.linux_6_1.virtualbox
  • linuxKernel.packages.linux_6_1.virtualboxGuestAdditions
  • linuxKernel.packages.linux_6_10.virtualbox
  • linuxKernel.packages.linux_6_10.virtualboxGuestAdditions
  • linuxKernel.packages.linux_6_11.virtualbox
  • linuxKernel.packages.linux_6_11.virtualboxGuestAdditions
  • linuxKernel.packages.linux_6_6.virtualbox
  • linuxKernel.packages.linux_6_6.virtualboxGuestAdditions
  • linuxKernel.packages.linux_latest_libre.virtualbox
  • linuxKernel.packages.linux_latest_libre.virtualboxGuestAdditions
  • linuxKernel.packages.linux_libre.virtualbox
  • linuxKernel.packages.linux_libre.virtualboxGuestAdditions
  • linuxKernel.packages.linux_lqx.virtualbox
  • linuxKernel.packages.linux_lqx.virtualboxGuestAdditions
  • linuxKernel.packages.linux_xanmod.virtualbox
  • linuxKernel.packages.linux_xanmod.virtualboxGuestAdditions
  • linuxKernel.packages.linux_xanmod_latest.virtualbox (linuxKernel.packages.linux_xanmod_stable.virtualbox)
  • linuxKernel.packages.linux_xanmod_latest.virtualboxGuestAdditions (linuxKernel.packages.linux_xanmod_stable.virtualboxGuestAdditions)
  • linuxKernel.packages.linux_zen.virtualbox
  • linuxKernel.packages.linux_zen.virtualboxGuestAdditions
  • virtualbox
  • virtualbox.modsrc
  • virtualboxExtpack
  • virtualboxHardened
  • virtualboxHardened.modsrc
  • virtualboxHeadless
  • virtualboxHeadless.modsrc
  • virtualboxWithExtpack
  • virtualboxWithExtpack.modsrc
---

Add a 👍 reaction to pull requests you find important.

Copy link
Contributor

@blitz blitz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good from the changes. Can't test it right now though.

Copy link
Contributor

@FriedrichAltheide FriedrichAltheide left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please remove the second commit

@FriedrichAltheide
Copy link
Contributor

@blitz Could you please create a PR once, you have released a (official) virtualboxKVM patch for the 7.0.22 version

@LeSuisse
Copy link
Contributor Author

Please remove the second commit

As you wish but this need to be backported to stable so I would have preferred to not a break a package.

@LeSuisse LeSuisse marked this pull request as ready for review October 24, 2024 14:49
@dasJ dasJ merged commit 299522b into NixOS:master Oct 25, 2024
59 of 60 checks passed
@LeSuisse LeSuisse deleted the virtualbox-7.0.22 branch October 25, 2024 09:45
@FriedrichAltheide FriedrichAltheide added the backport release-24.05 Backport PR automatically label Oct 25, 2024
Copy link
Contributor

Backport failed for release-24.05, because it was unable to cherry-pick the commit(s).

Please cherry-pick the changes locally and resolve any conflicts.

git fetch origin release-24.05
git worktree add -d .worktree/backport-350707-to-release-24.05 origin/release-24.05
cd .worktree/backport-350707-to-release-24.05
git switch --create backport-350707-to-release-24.05
git cherry-pick -x 299522b78a546b0238861cdad93f340f0b62b8fd

@bjornfor
Copy link
Contributor

Is virtualboxKvm an unimportant package that we're OK with breaking? Because this PR breaks it, and now I wonder whether the backport to stable should wait until virtualboxKvm is fixed, or not?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants