<div dir="ltr"><div>If anyone from Canonical here who maintains ubuntu-cloud.archive.canonical,</div><div><br></div><div>I can see the patch for CVE-2015-3456 updated to qemu-kvm package on Precise - Icehouse branch. </div><div><a href="https://launchpad.net/~ubuntu-cloud-archive/+archive/ubuntu/icehouse-staging/+build/7425816">https://launchpad.net/~ubuntu-cloud-archive/+archive/ubuntu/icehouse-staging/+build/7425816</a><br></div><div><br></div><div>But, on precise-havana it is not yet updated.</div><div>(Latest available is <a href="https://launchpad.net/~ubuntu-cloud-archive/+archive/ubuntu/havana-staging/+build/5955528">https://launchpad.net/~ubuntu-cloud-archive/+archive/ubuntu/havana-staging/+build/5955528</a>)</div><div>Is there a plan to update the package ?</div><div><br></div><div class="gmail_extra">Thanks,<br clear="all"><div><div class="gmail_signature">-Basil</div></div>
<br><div class="gmail_quote">On Wed, May 13, 2015 at 7:25 PM, Matt Van Winkle <span dir="ltr"><<a href="mailto:mvanwink@rackspace.com" target="_blank">mvanwink@rackspace.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">It would.  I'd test though.  Depending on the amount of RAM and the I/O of<br>
the underlying host, we saw that some larger instances could take longer<br>
to suspend/resume than shutdown/power up.  You maintain the state of the<br>
system, but may see longer "downtime" for the instance.  Something to<br>
think about.<br>
<br>
Thanks!<br>
<span class="HOEnZb"><font color="#888888">Matt<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
On 5/13/15 6:19 PM, "Favyen Bastani" <<a href="mailto:fbastani@perennate.com">fbastani@perennate.com</a>> wrote:<br>
<br>
>Would a virsh suspend/save/restore/resume operation accomplish similar<br>
>result as the localhost migration?<br>
><br>
>Best,<br>
>Favyen<br>
><br>
>On 05/13/2015 12:44 PM, Matt Van Winkle wrote:<br>
>> Yeah, something like that would be handy.<br>
>><br>
>> From: matt <<a href="mailto:matt@nycresistor.com">matt@nycresistor.com</a><mailto:<a href="mailto:matt@nycresistor.com">matt@nycresistor.com</a>>><br>
>> Date: Wednesday, May 13, 2015 10:29 AM<br>
>> To: "Daniel P. Berrange"<br>
>><<a href="mailto:berrange@redhat.com">berrange@redhat.com</a><mailto:<a href="mailto:berrange@redhat.com">berrange@redhat.com</a>>><br>
>> Cc: Matt Van Winkle<br>
>><<a href="mailto:mvanwink@rackspace.com">mvanwink@rackspace.com</a><mailto:<a href="mailto:mvanwink@rackspace.com">mvanwink@rackspace.com</a>>>,<br>
>>"<a href="mailto:openstack-operators@lists.openstack.org">openstack-operators@lists.openstack.org</a><mailto:<a href="mailto:openstack-operators@lists">openstack-operators@lists</a><br>
>>.<a href="http://openstack.org" target="_blank">openstack.org</a>>"<br>
>><<a href="mailto:openstack-operators@lists.openstack.org">openstack-operators@lists.openstack.org</a><mailto:<a href="mailto:openstack-operators@lists">openstack-operators@lists</a><br>
>>.<a href="http://openstack.org" target="_blank">openstack.org</a>>><br>
>> Subject: Re: [Openstack-operators] Venom vulnerability<br>
>><br>
>> honestly that seems like a very useful feature to ask for...<br>
>>specifically for upgrading qemu.<br>
>><br>
>> -matt<br>
>><br>
>> On Wed, May 13, 2015 at 11:19 AM, Daniel P. Berrange<br>
>><<a href="mailto:berrange@redhat.com">berrange@redhat.com</a><mailto:<a href="mailto:berrange@redhat.com">berrange@redhat.com</a>>> wrote:<br>
>> On Wed, May 13, 2015 at 03:08:47PM +0000, Matt Van Winkle wrote:<br>
>>> So far, your assessment is spot on from what we've seen.  A migration<br>
>>> (if you have live migrate that's even better) should net the same<br>
>>>result<br>
>>> for QEMU.  Some have floated the idea of live migrate within the same<br>
>>> host.  I don't know if nova out of the box would support such a thing.<br>
>><br>
>> Localhost migration (aka migration within the same host) is not<br>
>>something<br>
>> that is supported by libvirt/KVM. Various files QEMU has on disk are<br>
>>based<br>
>> on the VM name/uuid and you can't have 2 QEMU processes on the host<br>
>>having<br>
>> the files at the same time, which precludes localhost migration working.<br>
>><br>
>> Regards,<br>
>> Daniel<br>
>><br>
>><br>
>><br>
>> -----BEGIN PGP MESSAGE----- Version: GnuPG v1 Comment: Charset:<br>
>>us-ascii<br>
>> hQIMA4ToeuPbGFzLAQ//WKATa6VRGKJKq7zAcUTO0tS8Lgq5zuo1buc2pJtbPKXi<br>
>> pFmHpgTsXxoU3LNhfWelAToCQdacVLUw5OiFsWyoVsjAcuRzMrN+l8WHYG4jZDGs<br>
>> bXCUp4XwShex35/vmI15NTAKrmbgIJZRi80sewCZ8H13rei86TPKA5b1C9SFxiqq<br>
>> KGmntJdiEyk+x2SOz5xvZVx/29XryUSBXo6YAVQmW4AZrrdVdkRxDKCX3tw90UZ+<br>
>> RCibGl1nac4n2rrXZ+izKcq6d+CYo28yBaEJ5zecrU1K9M/rZwyVWnr5NTP0bs0B<br>
>> EOBV+0YsaBJdfbdrntKGUZCKVta4QdX9mOIQ7GYM/DP3IxHywFKfcwjG0iRjHYQG<br>
>> sNCK0ymhr+eNcBKWHjyVqvy/W5IIep+ES1Y7xhmwqPfWEraNQ+Scc9T6i7mWAaam<br>
>> dn7fVaO3dOHEoKVGX6Z+TtQS+FjesrgtOtvEeonVAkQLNEBVnQcMaMOrz+Ia1AXf<br>
>> +SwkcksDaqylXC1TqTLjyA7ceEHWqPL7d6EfIM7dBT/tg0h5WL2XgoJlFddSXDoR<br>
>> 99b2Arc9jaG+tJamvRO+M8Ky8uVuD5pF68wDwfvPqHbzSzzt3fmmkQkOVmtNLkjp<br>
>> ZAGDxV/0+xhurdz4HFDz6q3ShpgREsgBEOd8uY7UCn67nRZbrS4YtdUIV25dhknS<br>
>> 6gGkwfhs5IR99F/IvQUXsUs1m5DCWZI0GkWEaTcTEJfNoYHLPH+vLdtzupNz7ihp<br>
>> sNtie42q3urYLW5irAFeTW8jyjS4V5TPMMUXMvp5DG4eOGGCoKiZQhmT3JJB3PHe<br>
>> 5kghWgOlRQyK9trkH1zS8cgpXPhL+g/LGRfrp+xH7E7Hn1DLMizeQargFpcLmpdR<br>
>> KHQQCHlBuB4gTQ0n/ai5zRVrioH+6GVMVedUxsYTMlrVWNGocYVZ/lzjHdDGVPiQ<br>
>> JoxmMxVqL8icPu21FoIXGKiTA6VI0cAmugpQDXFVuk+HVYyYGtj9swmPyaR7ykXU<br>
>> 1+4KAyBXsmz4y/mQxKsSVZnlp+cq9Y6iR7IPcj06KMeTF61Zc6sJZ0aIDl6IzzOB<br>
>> UErMtFTKuAMAFPmB2wZ2kMsuz5K48BZcDSeO6PT6fbsWtQvmRK+Fqjf8iLtpLnEj<br>
>> 2aG0hKeDTJkZKJOtaHoePx1MBrfRS1kCSAhjTCIxgSuIKLsRx9M+8KfqB+suYXUA<br>
>> RbrSrOyvl16YfUmTaWdYS+PdKuLYEVHViqZecvc30jALJoQOcvoWO7Kwzh4Tl4H9<br>
>> jeSA1+lpV0P25tm7x+PbpAVgbX0aBD4rs2TYU79MersBvL8trm3q6UcB0Bcud/XQ<br>
>> rUTUa7xUgS8XO+EsU6WMKmRZ+Usl+yTqaXH4eTMMAAL1b2Kq9Lr3RZP/zuQpYfiG<br>
>> aSfX8al6YJQRGRVwYORbeUjcOw5fioash8Xf1OEpj0fYLGbsqhRUZU6UbADjEcHo<br>
>> YJID1xvBUmw149iCbOTwHb1rTfw2t8VThkfIxbSTd7t/urYNn5F5H1dhWocvs+oR<br>
>> cd4GKZJjvQcT2/RH8taspQjWNL5asRQvwdb6ZUYQDa5G6o2N3pjIrP9Itue8Iaf6<br>
>> B/xZ6MnFnAB821YiT1V0KbX7FB8bE6HE9z7jR1zpqBA3LbPxVtst2AxenVxbCSQT<br>
>> scA5c4YoXXgxPbrCyX22lyAKwuYEaRa7KrPVjrJoyjDDK1uFD0JRqzokJcS/7dBY<br>
>> F9xrz5H9yRoyVwy/pG9uEdoQkGth3DiOBkqUMYrvipqP0AKHRHcASdL/3fbgdB9Q<br>
>> bmCwWVTyUVbmqztawJ8Xc9+QRk1wEbLvt3df9DZkUT8lqR9JUt4xLWpMvhOhsIVQ<br>
>> iXFaeSoZTpa7B8NzTpJPfCrZtTYnZxzHewxg0gViHQPSv+LmvpR2Z3k6CkgRdqKE<br>
>> 1vM/+Ih2Ksc+Yyd5T40IObyaTmSigXnIkKv3vHQtaZaLmwiZRFJY8EmLASSz5/o/<br>
>> LUNMH1CPPvj00W3rLzMHDnYu2ZhWETpQBGjNUWcQnzo6Vfg3SBXse3WbZu73Ix2f<br>
>> O+kMHjMtB9Nf4URij4D3obLpSVZ1F95wyS63yTuS7nncSNnvbm891946F4/k/J79<br>
>> 4fsPVdOA3JSrR9nl10yKsxlfbeTh3saPP2GvDd7TWmC1AdCej64RyyNojJONvbi2<br>
>> su4esVJicnUZM0/d4nqhiYacVxhDU4PnWcy9xISEwgKT0LTlC8VWO8qdRqa5RFlq<br>
>> ewUoE1pCoxapKYOv+GC4DKHmGXp4xcpDnQvQFqcG7ntlZGPmfu4kyCguniCGF0yV<br>
>> nbffVuNUQYNlBt9Y1X9YBZX+DAlx822qOXWDnqe9yhPlEcH7RxmXqdQlqDDZZDhs<br>
>> QhJvqVuBSRxmEoi4K/vE04HPa79L39h40jX1NmGuBjwhst1+1fYfHHS16PqlbNZF<br>
>> H1KuELxVkK4HKhyxr5xTGubLHjIC13tMe73bQadFod5cUiZj+fhRSTzHrAUru9Jk<br>
>> HvUDPF3b9R2fcPRqD5Mtg2gjRDsgWvrODoLW+tCdNuBf3eg3JJYzlFkJU1wiMaml<br>
>> XdQwiGD8m0hABnae7RFODogXpzfKkeFIRmV7vWQqkRc4LUBE0+diw61qaIJE+9d8<br>
>> 3NGdESlAleI9hMQVSuwzb5vEn5d4+qPoi1/LhlToho2WJo1By9KkAIUY4eSo8jih<br>
>> CY+QgrLGZ6CRDLkkj7hVIDdThVcTxesPeDL4DStdee/d2g1PLzWMsQlp0/NDyDZx<br>
>> azBbdEZub5/el9Buzgmrv/NgKP3GYLiexFcMe4B9p8Q7AqbtE7oPxOZD4a6EVVe0<br>
>> 3u6WKkNOzqDgLKUmt6EAYI9zxwKz/r8K4UKahoi9abrmGwvsrApICJfThC74aw== =QMaw<br>
>>-----END<br>
>> PGP MESSAGE-----<br>
>><br>
>><br>
>><br>
>> -----BEGIN PGP MESSAGE-----<br>
>> Version: GnuPG v1<br>
>> Comment: Charset: us-ascii<br>
>><br>
>> hQIMA4ToeuPbGFzLARAAg0zb38BESkbvvLbom+Lcf+NpIfxCZvsok8DRTEeEO3v5<br>
>> sCsiK50E/IwxRpdO0IhqfOmMhJDmHAOD8emqgNMH6dppiV2ftuxraTU27+I8Kmdi<br>
>> o8VUDb98XvH1DjsjcKLGWwM5+dKqtnh7adiJwsRRiEswuumtsh+eH5R9D7928kgV<br>
>> ZZn6b615jGulXMeIf6BuSEfLXBiSE5hgYfizcakFzdW/gm+8URGUQYGBlwm/qQoV<br>
>> f37TmSqrDiM1nVn7KF2NGdGG72NBtgkQ05GnNiYN+1L2wDnegwhHHnQzz56VJOSJ<br>
>> FcDnIDms3JhV0FxjsWTeFwvvWBYahd7EEgzTO+xY3rntU9uiQS60HHh1l9RTNyVt<br>
>> AlTmkH0BnEfzeWp/Yq5ynCQ3Sosy4LuZucmwvZeFeVtksArehSW8Gpe1p5RaP2Gy<br>
>> 12EMp9EaexKL73W4F0XQpgljNt0kKeqE16M7xE1dlxtcTU6ftwJj75L+eFbRYJYQ<br>
>> 09M75ui0PUAFidTljjx1t9ChPwjJzEZ/krm3YI193NbxXT2cL5zCwOV3XILKL8q1<br>
>> FVbUDREQqaZi09sPst06Z3ODUVFMgCG3OpQcsyIQnYhMMhWxvAsg4UIh/vagkeFL<br>
>> oHtVU+AWsO4RMqfrDUvNMUzUpe15mR61A8qGooEF56IehvCPh1obPQnGzS622f7S<br>
>> jwGgCLs9PZAs/f7S0gKKQtExxuK1cvXbgR8L6KgkNFZxdXJyiLdCZ34VURqoQ+zu<br>
>> nrdRbY+kVNx3+slu5Qlyi2RMNsrmE6Y9V2YNPcwXBHLDgGgvtyqsE7zUkWrGxZYQ<br>
>> AztYQPdi6fU8K2muzJDS+f5j9F4YPcotARHv0H3KHO+ZJrxSX1R8G8eG1YbtFrLG<br>
>> =aZhd<br>
>> -----END PGP MESSAGE-----<br>
>><br>
<br>
<br>
_______________________________________________<br>
OpenStack-operators mailing list<br>
<a href="mailto:OpenStack-operators@lists.openstack.org">OpenStack-operators@lists.openstack.org</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-operators" target="_blank">http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-operators</a><br>
</div></div></blockquote></div><br></div></div>