Sync to SGX 1.33.2

Bug #1936240 reported by Tim Gardner
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux-azure (Ubuntu)
Invalid
Undecided
Unassigned
Focal
Fix Released
Medium
Tim Gardner
Groovy
Won't Fix
Medium
Unassigned

Bug Description

SRU Justification

[Impact]

Microsoft has requested updating ubuntu/sgx support to 1.33.2.

[Fix]

https://github.com/intel/SGXDataCenterAttestationPrimitives ld_133
56a183872786d9ad3f2f395dc1d740ccb22d01a1 Linux Driver: Version 1.33.2

[Test Case]

Microsoft tested
Look for "sgx: intel_sgx: Intel SGX DCAP Driver v1.33.2" in dmesg.

[Where problems could occur]

SGX functionality could regress

[Other Info]

SF: #00314640

CVE References

Tim Gardner (timg-tpi)
Changed in linux-azure (Ubuntu):
status: New → Invalid
Changed in linux-azure (Ubuntu Focal):
status: New → In Progress
Changed in linux-azure (Ubuntu Groovy):
status: New → In Progress
Changed in linux-azure (Ubuntu Focal):
importance: Undecided → Medium
Changed in linux-azure (Ubuntu Groovy):
importance: Undecided → Medium
Changed in linux-azure (Ubuntu Focal):
assignee: nobody → Tim Gardner (timg-tpi)
Changed in linux-azure (Ubuntu Groovy):
assignee: nobody → Tim Gardner (timg-tpi)
Tim Gardner (timg-tpi)
description: updated
Tim Gardner (timg-tpi)
Changed in linux-azure (Ubuntu Groovy):
status: In Progress → Won't Fix
assignee: Tim Gardner (timg-tpi) → nobody
Revision history for this message
Tim Gardner (timg-tpi) wrote :
Tim Gardner (timg-tpi)
Changed in linux-azure (Ubuntu Focal):
status: In Progress → Fix Committed
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote :

This bug is awaiting verification that the kernel in -proposed solves the problem. Please test the kernel and update this bug with the results. If the problem is solved, change the tag 'verification-needed-focal' to 'verification-done-focal'. If the problem still exists, change the tag 'verification-needed-focal' to 'verification-failed-focal'.

If verification is not done by 5 working days from today, this fix will be dropped from the source code, and this bug will be closed.

See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you!

tags: added: verification-needed-focal
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (37.7 KiB)

This bug was fixed in the package linux-azure - 5.4.0-1058.60

---------------
linux-azure (5.4.0-1058.60) focal; urgency=medium

  * focal/linux-azure: 5.4.0-1058.60 -proposed tracker (LP: #1942117)

  * linux-azure: main(): sched_setscheduler(): Operation not permitted
    (LP: #1942092)
    - Revert "UBUNTU: [Config] azure: CONFIG_RT_GROUP_SCHED=y"

  [ Ubuntu: 5.4.0-84.94 ]

  * focal/linux: 5.4.0-84.94 -proposed tracker (LP: #1941767)
  * Server boot failure after adding checks for ACPI IRQ override (LP: #1941657)
    - Revert "ACPI: resources: Add checks for ACPI IRQ override"

linux-azure (5.4.0-1057.59) focal; urgency=medium

  * focal/linux-azure: 5.4.0-1057.59 -proposed tracker (LP: #1939775)

  * Focal update: v5.4.129 upstream stable release (LP: #1936242)
    - [Config] enable CONFIG_SYSTEM_REVOCATION_LIST

  * linux-azure Enable CONFIG_RT_GROUP_SCHED (LP: #1939024)
    - [Config] azure: CONFIG_RT_GROUP_SCHED=y

  * Sync to SGX 1.33.2 (LP: #1936240)
    - SAUCE: ubuntu/sgx: backport fixes to 1.33
    - SAUCE: ubuntu/sgx: missing synchronize_srcu call before cleanup
    - SAUCE: ubuntu/sgx: fix a synchronization issue for mmput
    - SAUCE: ubuntu/sgx: look for exported symbols in Makefile
    - SAUCE: ubuntu/sgx: hardening compiler options
    - SAUCE: ubuntu/sgx: Fix signed integer overflow on shift
    - SAUCE: ubuntu/sgx: move use space header
    - SAUCE: ubuntu/sgx: Version 1.33.2

  [ Ubuntu: 5.4.0-83.93 ]

  * focal/linux: 5.4.0-83.93 -proposed tracker (LP: #1940159)
  * fails to launch linux L2 guests on AMD (LP: #1940134) // CVE-2021-3653
    - KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl
      (CVE-2021-3653)
  * fails to launch linux L2 guests on AMD (LP: #1940134)
    - SAUCE: Revert "UBUNTU: SAUCE: KVM: nSVM: avoid picking up unsupported bits
      from L2 in int_ctl"

  [ Ubuntu: 5.4.0-82.92 ]

  * focal/linux: 5.4.0-82.92 -proposed tracker (LP: #1939799)
  * Packaging resync (LP: #1786013)
    - debian/dkms-versions -- update from kernel-versions (main/2021.08.16)
  * CVE-2021-3656
    - SAUCE: KVM: nSVM: always intercept VMLOAD/VMSAVE when nested
  * CVE-2021-3653
    - SAUCE: KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl
  * [regression] USB device is not detected during boot (LP: #1939638)
    - SAUCE: Revert "usb: core: reduce power-on-good delay time of root hub"
  * dev_forward_skb: do not scrub skb mark within the same name space
    (LP: #1935040)
    - dev_forward_skb: do not scrub skb mark within the same name space
  * XPS 9510 (TGL) Screen Brightness could not be changed (LP: #1933566)
    - SAUCE: drm/i915: Force DPCD backlight mode for Dell XPS 9510(TGL)
  * Acer Aspire 5 sound driver issues (LP: #1930188)
    - ALSA: hda/realtek: headphone and mic don't work on an Acer laptop
  * Sony Dualshock 4 usb dongle crashes the whole system (LP: #1935846)
    - HID: sony: Workaround for DS4 dongle hotplug kernel crash.
  * [21.10 FEAT] KVM: Provide a secure guest indication (LP: #1933173)
    - s390/uv: add prot virt guest/host indication files
    - s390/uv: fix prot virt host indication compilation
  * Skip rtcpie test in kselftests/timers if the default RTC device does ...

Changed in linux-azure (Ubuntu Focal):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.