Bug 22533 - Update request: kernel 4.14.18
Summary: Update request: kernel 4.14.18
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK, MGA6-32-OK
Keywords: advisory, validated_update
Depends on: 22525
Blocks: 22390
  Show dependency treegraph
 
Reported: 2018-02-06 07:28 CET by Thomas Backlund
Modified: 2018-02-11 19:43 CET (History)
7 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2018-02-06 07:28:11 CET
Note, as the summary says, this update will be about the upcoming 4.14.18, but as we need a nice way to test the new gcc in bug 22525, and we want the retpoline stuff chacked, I've added current 4.14.18-rc1 in this build...

So you can start testing with this, and also test that dkms packages builds and still works with new gcc against this kernel...

So, Packages to test so far:

SRPMS:
kernel-4.14.17-2.mga6.src.rpm
kernel-userspace-headers-4.14.17-2.mga6.src.rpm

kmod-vboxadditions-5.2.6-5.mga6.src.rpm
kmod-virtualbox-5.2.6-5.mga6.src.rpm
kmod-xtables-addons-2.13-15.mga6.src.rpm

wireguard-tools-0.0.20180202-1.mga6.src.rpm

i586:
cpupower-4.14.17-2.mga6.i586.rpm
cpupower-devel-4.14.17-2.mga6.i586.rpm
kernel-desktop-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-desktop586-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-latest-4.14.17-2.mga6.i586.rpm
kernel-desktop586-latest-4.14.17-2.mga6.i586.rpm
kernel-desktop-devel-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-desktop-devel-latest-4.14.17-2.mga6.i586.rpm
kernel-desktop-latest-4.14.17-2.mga6.i586.rpm
kernel-doc-4.14.17-2.mga6.noarch.rpm
kernel-server-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-server-devel-4.14.17-2.mga6-1-1.mga6.i586.rpm
kernel-server-devel-latest-4.14.17-2.mga6.i586.rpm
kernel-server-latest-4.14.17-2.mga6.i586.rpm
kernel-source-4.14.17-2.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.17-2.mga6.noarch.rpm
kernel-userspace-headers-4.14.17-2.mga6.i586.rpm
perf-4.14.17-2.mga6.i586.rpm

vboxadditions-kernel-4.14.17-desktop-2.mga6-5.2.6-5.mga6.i586.rpm
vboxadditions-kernel-4.14.17-desktop586-2.mga6-5.2.6-5.mga6.i586.rpm
vboxadditions-kernel-4.14.17-server-2.mga6-5.2.6-5.mga6.i586.rpm
vboxadditions-kernel-desktop586-latest-5.2.6-5.mga6.i586.rpm
vboxadditions-kernel-desktop-latest-5.2.6-5.mga6.i586.rpm
vboxadditions-kernel-server-latest-5.2.6-5.mga6.i586.rpm

virtualbox-kernel-4.14.17-desktop-2.mga6-5.2.6-5.mga6.i586.rpm
virtualbox-kernel-4.14.17-desktop586-2.mga6-5.2.6-5.mga6.i586.rpm
virtualbox-kernel-4.14.17-server-2.mga6-5.2.6-5.mga6.i586.rpm
virtualbox-kernel-desktop586-latest-5.2.6-5.mga6.i586.rpm
virtualbox-kernel-desktop-latest-5.2.6-5.mga6.i586.rpm
virtualbox-kernel-server-latest-5.2.6-5.mga6.i586.rpm

xtables-addons-kernel-4.14.17-desktop-2.mga6-2.13-15.mga6.i586.rpm
xtables-addons-kernel-4.14.17-desktop586-2.mga6-2.13-15.mga6.i586.rpm
xtables-addons-kernel-4.14.17-server-2.mga6-2.13-15.mga6.i586.rpm
xtables-addons-kernel-desktop586-latest-2.13-15.mga6.i586.rpm
xtables-addons-kernel-desktop-latest-2.13-15.mga6.i586.rpm
xtables-addons-kernel-server-latest-2.13-15.mga6.i586.rpm

wireguard-tools-0.0.20180202-1.mga6.i586.rpm



x86_64:
cpupower-4.14.17-2.mga6.x86_64.rpm
cpupower-devel-4.14.17-2.mga6.x86_64.rpm
kernel-desktop-4.14.17-2.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-4.14.17-2.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-latest-4.14.17-2.mga6.x86_64.rpm
kernel-desktop-latest-4.14.17-2.mga6.x86_64.rpm
kernel-doc-4.14.17-2.mga6.noarch.rpm
kernel-server-4.14.17-2.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-4.14.17-2.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-latest-4.14.17-2.mga6.x86_64.rpm
kernel-server-latest-4.14.17-2.mga6.x86_64.rpm
kernel-source-4.14.17-2.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.17-2.mga6.noarch.rpm
kernel-userspace-headers-4.14.17-2.mga6.x86_64.rpm
perf-4.14.17-2.mga6.x86_64.rpm

vboxadditions-kernel-4.14.17-desktop-2.mga6-5.2.6-5.mga6.x86_64.rpm
vboxadditions-kernel-4.14.17-server-2.mga6-5.2.6-5.mga6.x86_64.rpm
vboxadditions-kernel-desktop-latest-5.2.6-5.mga6.x86_64.rpm
vboxadditions-kernel-server-latest-5.2.6-5.mga6.x86_64.rpm

virtualbox-kernel-4.14.17-desktop-2.mga6-5.2.6-5.mga6.x86_64.rpm
virtualbox-kernel-4.14.17-server-2.mga6-5.2.6-5.mga6.x86_64.rpm
virtualbox-kernel-desktop-latest-5.2.6-5.mga6.x86_64.rpm
virtualbox-kernel-server-latest-5.2.6-5.mga6.x86_64.rpm

xtables-addons-kernel-4.14.17-desktop-2.mga6-2.13-15.mga6.x86_64.rpm
xtables-addons-kernel-4.14.17-server-2.mga6-2.13-15.mga6.x86_64.rpm
xtables-addons-kernel-desktop-latest-2.13-15.mga6.x86_64.rpm
xtables-addons-kernel-server-latest-2.13-15.mga6.x86_64.rpm

wireguard-tools-0.0.20180202-1.mga6.x86_64.rpm
Comment 1 Thomas Backlund 2018-02-06 07:30:29 CET
Now, I've had gcc 5.5.0 installed on 2 hosts since last saturday, and a 4.4.17-1 built with the new gcc running on 2 systems since then, and it seems to behave... but YMMV...

Depends on: (none) => 22525

Comment 2 Thomas Backlund 2018-02-06 07:44:26 CET
And a Meltdown / Spectre status check with this kernel (and the new gcc)

on an Intel system:

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
* Kernel has array_index_mask_nospec:  YES  (1 occurence(s) found of 64 bits array_index_mask_nospec())
> STATUS:  NOT VULNERABLE  (Mitigation: __user pointer sanitization)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
* Mitigation 1
  * Kernel is compiled with IBRS/IBPB support:  NO 
  * Currently enabled features
    * IBRS enabled for Kernel space:  NO 
    * IBRS enabled for User space:  NO 
    * IBPB enabled:  NO 
* Mitigation 2
  * Kernel compiled with retpoline option:  YES 
  * Kernel compiled with a retpoline-aware compiler:  YES  (kernel reports full retpoline compilation)
  * Retpoline enabled:  NO 
> STATUS:  NOT VULNERABLE  (Mitigation: Full generic retpoline)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
* Kernel supports Page Table Isolation (PTI):  YES 
* PTI enabled and active:  YES 
* Running as a Xen PV DomU:  NO 
> STATUS:  NOT VULNERABLE  (Mitigation: PTI)



and on an Amd system:

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
> STATUS:  NOT VULNERABLE  (Mitigation: __user pointer sanitization)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
* Mitigation 1
  * Kernel is compiled with IBRS/IBPB support:  NO 
  * Currently enabled features
    * IBRS enabled for Kernel space:  NO 
    * IBRS enabled for User space:  NO 
    * IBPB enabled:  NO 
* Mitigation 2
  * Kernel compiled with retpoline option:  YES 
  * Kernel compiled with a retpoline-aware compiler:  YES  (kernel reports full retpoline compilation)
  * Retpoline enabled:  NO 
> STATUS:  NOT VULNERABLE  (Mitigation: Full AMD retpoline)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Mitigated according to the /sys interface:  YES  (kernel confirms that your CPU is unaffected)
* Kernel supports Page Table Isolation (PTI):  YES 
* PTI enabled and active:  NO 
* Running as a Xen PV DomU:  NO 
> STATUS:  NOT VULNERABLE  (your CPU vendor reported your CPU model as not vulnerable)



so 3/3 atatus: NOT_VULNERABLE
Thomas Backlund 2018-02-06 14:25:18 CET

Blocks: (none) => 22390

Comment 3 Len Lawrence 2018-02-07 21:00:00 CET
Updated gcc and then the kernel packages.
dkms builds looked successful including virtualbox modules.
Clean reboot.

System:    Host: markab Kernel: 4.14.17-desktop-2.mga6 x86_64
Machine:   Device: laptop System: GIGABYTE product: X5
Network:   Card-1: Qualcomm Atheros Killer E220x Gigabit Ethernet Controller
           driver: alx
           Card-2: Intel Wireless 7265 driver: iwlwifi
Graphics:  Card-1: NVIDIA GM204M [GeForce GTX 965M]
           Card-2: NVIDIA GM204M [GeForce GTX 965M]
           GLX Version: 4.5.0 NVIDIA 384.111
RAM:       15.62 GB

Working desktop.  Mounted NFS share.  No vdi on this machine so virtualbox not tested.  Hardware stress tests ran fine.  No problems so far.

CC: (none) => tarazed25

Comment 4 Thomas Backlund 2018-02-08 10:02:33 CET
OK, final 4.14.18 is now out wit some added fixes ready to be fully tested, validated and pushed out...

Advisory to follow...


SRPMS:
kernel-4.14.18-1.mga6.src.rpm
kernel-userspace-headers-4.14.18-1.mga6.src.rpm

kmod-vboxadditions-5.2.6-6.mga6.src.rpm
kmod-virtualbox-5.2.6-6.mga6.src.rpm
kmod-xtables-addons-2.13-16.mga6.src.rpm

wireguard-tools-0.0.20180202-1.mga6.src.rpm



i586:
cpupower-4.14.18-1.mga6.i586.rpm
cpupower-devel-4.14.18-1.mga6.i586.rpm
kernel-desktop-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-latest-4.14.18-1.mga6.i586.rpm
kernel-desktop586-latest-4.14.18-1.mga6.i586.rpm
kernel-desktop-devel-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-desktop-devel-latest-4.14.18-1.mga6.i586.rpm
kernel-desktop-latest-4.14.18-1.mga6.i586.rpm
kernel-doc-4.14.18-1.mga6.noarch.rpm
kernel-server-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-4.14.18-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-latest-4.14.18-1.mga6.i586.rpm
kernel-server-latest-4.14.18-1.mga6.i586.rpm
kernel-source-4.14.18-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.18-1.mga6.noarch.rpm
kernel-userspace-headers-4.14.18-1.mga6.i586.rpm
perf-4.14.18-1.mga6.i586.rpm

vboxadditions-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.i586.rpm
vboxadditions-kernel-4.14.18-desktop586-1.mga6-5.2.6-6.mga6.i586.rpm
vboxadditions-kernel-4.14.18-server-1.mga6-5.2.6-6.mga6.i586.rpm
vboxadditions-kernel-desktop586-latest-5.2.6-6.mga6.i586.rpm
vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.i586.rpm
vboxadditions-kernel-server-latest-5.2.6-6.mga6.i586.rpm

virtualbox-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.i586.rpm
virtualbox-kernel-4.14.18-desktop586-1.mga6-5.2.6-6.mga6.i586.rpm
virtualbox-kernel-4.14.18-server-1.mga6-5.2.6-6.mga6.i586.rpm
virtualbox-kernel-desktop586-latest-5.2.6-6.mga6.i586.rpm
virtualbox-kernel-desktop-latest-5.2.6-6.mga6.i586.rpm
virtualbox-kernel-server-latest-5.2.6-6.mga6.i586.rpm

xtables-addons-kernel-4.14.18-desktop-1.mga6-2.13-16.mga6.i586.rpm
xtables-addons-kernel-4.14.18-desktop586-1.mga6-2.13-16.mga6.i586.rpm
xtables-addons-kernel-4.14.18-server-1.mga6-2.13-16.mga6.i586.rpm
xtables-addons-kernel-desktop586-latest-2.13-16.mga6.i586.rpm
xtables-addons-kernel-desktop-latest-2.13-16.mga6.i586.rpm
xtables-addons-kernel-server-latest-2.13-16.mga6.i586.rpm

wireguard-tools-0.0.20180202-1.mga6.i586.rpm



x86_64:
cpupower-4.14.18-1.mga6.x86_64.rpm
cpupower-devel-4.14.18-1.mga6.x86_64.rpm
kernel-desktop-4.14.18-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-4.14.18-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-latest-4.14.18-1.mga6.x86_64.rpm
kernel-desktop-latest-4.14.18-1.mga6.x86_64.rpm
kernel-doc-4.14.18-1.mga6.noarch.rpm
kernel-server-4.14.18-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-4.14.18-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-latest-4.14.18-1.mga6.x86_64.rpm
kernel-server-latest-4.14.18-1.mga6.x86_64.rpm
kernel-source-4.14.18-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.18-1.mga6.noarch.rpm
kernel-userspace-headers-4.14.18-1.mga6.x86_64.rpm
perf-4.14.18-1.mga6.x86_64.rpm

vboxadditions-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.x86_64.rpm
vboxadditions-kernel-4.14.18-server-1.mga6-5.2.6-6.mga6.x86_64.rpm
vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.x86_64.rpm
vboxadditions-kernel-server-latest-5.2.6-6.mga6.x86_64.rpm

virtualbox-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.x86_64.rpm
virtualbox-kernel-4.14.18-server-1.mga6-5.2.6-6.mga6.x86_64.rpm
virtualbox-kernel-desktop-latest-5.2.6-6.mga6.x86_64.rpm
virtualbox-kernel-server-latest-5.2.6-6.mga6.x86_64.rpm

xtables-addons-kernel-4.14.18-desktop-1.mga6-2.13-16.mga6.x86_64.rpm
xtables-addons-kernel-4.14.18-server-1.mga6-2.13-16.mga6.x86_64.rpm
xtables-addons-kernel-desktop-latest-2.13-16.mga6.x86_64.rpm
xtables-addons-kernel-server-latest-2.13-16.mga6.x86_64.rpm

wireguard-tools-0.0.20180202-1.mga6.x86_64.rpm
Comment 5 William Kenney 2018-02-08 19:34:52 CET
In a Vbox client, M6, Mate, 32-bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 4.14.16-desktop-1.mga6 #1 SMP Wed Jan 31 19:52:46 UTC 2018 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.16-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-4.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.16-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing

[root@localhost wilcal]# uname -a
Linux localhost 4.14.18-desktop-1.mga6 #1 SMP Thu Feb 8 00:20:19 UTC 2018 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.18-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.18-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

CC: (none) => wilcal.int

Comment 6 William Kenney 2018-02-08 20:07:28 CET
update candidate: kernel

---------------- Description --------------

Description of problem:

xxxxxx

---------------- test procedure -----------

- cpupower-4.14.13-1.mga6.i586
- dracut-044-11.1.mga6.i586
- kernel-desktop-4.14.13-1.mga6-1-1.mga6.i586
- kernel-desktop-latest-4.14.13-1.mga6.i586
- microcode-0.20180108-1.mga6.nonfree.noarch
- vboxadditions-kernel-4.14.13-desktop-1.mga6-5.2.2-7.mga6.i586
- vboxadditions-kernel-desktop-latest-5.2.2-7.mga6.i586

- cpupower-4.14.13-1.mga6.x86_64
- dracut-044-11.1.mga6.x86_64
- kernel-desktop-4.14.13-1.mga6-1-1.mga6.x86_64
- kernel-desktop-latest-4.14.13-1.mga6.x86_64
- microcode-0.20180108-1.mga6.nonfree.noarch
- vboxadditions-kernel-4.14.13-desktop-1.mga6-5.2.2-7.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.2-7.mga6.x86_64

---------------- Comment 5 ----------------

In a Vbox client, M6, Mate, 32-bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 4.14.16-desktop-1.mga6 #1 SMP Wed Jan 31 19:52:46 UTC 2018 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.16-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-4.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.16-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing

[root@localhost wilcal]# uname -a
Linux localhost 4.14.18-desktop-1.mga6 #1 SMP Thu Feb 8 00:20:19 UTC 2018 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.18-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.18-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

---------------- Comment 6 ----------------

In a Vbox client, M6, Mate, 64-bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 4.14.16-desktop-1.mga6 #1 SMP Wed Jan 31 20:50:08 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.16-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-4.mga6.x86_64 is already installed
Marking vboxadditions-kernel-desktop-latest as manually installed, it won't be auto-orphaned
writing /var/lib/rpm/installed-through-deps.list
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.16-1.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing

[root@localhost wilcal]# uname -a
Linux localhost 4.14.18-desktop-1.mga6 #1 SMP Wed Feb 7 23:14:33 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.18-1.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 7 Thomas Andrews 2018-02-08 23:25:48 CET
On real hardware, HP Probook 6550b, i3 processor, 8GB, Intel graphics, Intel wifi.

One 64-bit Plasma install, with virtualbox, using the desktop kernel. One 32-bit Plasma install, without virtualbox, with both desktop and server kernels installed. 

64-bit: Everything looks good, including virtualbox. Windows XP guest updating antivirus as I type this.

32-bit: Everything looks good, except that Bug #22528, suspend/resume, is still valid.

CC: (none) => andrewsfarm

Comment 8 Len Lawrence 2018-02-09 02:06:20 CET
Installed desktop kernel packages and rebooted to Mate desktop.
System:    Host: vega Kernel: 4.14.18-desktop-1.mga6 x86_64
CPU:       Quad core Intel Core i7-4790K (-HT-MCP-) speed/max: 4399/4400 MHz
Machine:   Device: desktop Mobo: Gigabyte model: G1.Sniper Z97 v: x.x
Graphics:  Card-2: NVIDIA GK104 [GeForce GTX 770]
           GLX Version: 4.5.0 NVIDIA 384.111
Network:   Card-1: Qualcomm Atheros Killer E220x Gigabit Ethernet Controller
           driver: alx
RAM:       15.35 GB

Ran stress tests and glmark2.
Networking, network shares and common desktop applications working well.
Virtualbox running fine - two guests running at the same time, mga5:i586 and mga6:x86_64.  Freeview HD TV coming in loud and clear off a roof mounted aerial.
LibreOffice sent a page to HP wifi printer.  lpr command worked fine to the same printer.
$ lpr -Pokda -o lpi=8 -o cpi=17 -o page-left=10 -o page-top=10 manifest
Comment 9 Herman Viaene 2018-02-09 11:38:54 CET
MGA6-32 on Dell Latitude D600 Mate
No installation issues
Running usual apps for text, pdf, pictures, movies, music all OK. Newspaper site displays text, cartoons, video OK.
No obvious problems seen.

CC: (none) => herman.viaene

Comment 10 James Kerr 2018-02-09 15:47:47 CET
On mga6-64 plasma

packages installed cleanly:
- cpupower-4.14.18-1.mga6.x86_64
- kernel-desktop-4.14.18-1.mga6-1-1.mga6.x86_64
- kernel-desktop-latest-4.14.18-1.mga6.x86_64
- kernel-userspace-headers-4.14.18-1.mga6.x86_64
- virtualbox-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.6-6.mga6.x86_64

system re-booted normally
$ uname -r
4.14.18-desktop-1.mga6

virtualbox and client launched normally

tested commonly used applications
no regressions noted

OK for mga6-64 on this system:

Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 
Card: Intel HD Graphics 530
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
PC-BIOS (legacy) boot
GPT partitions

CC: (none) => jim

Comment 11 James Kerr 2018-02-09 15:49:26 CET
on mga6-32 plasma in a vbox VM

packages installed cleanly:
- cpupower-4.14.18-1.mga6.i586
- kernel-desktop-4.14.18-1.mga6-1-1.mga6.i586
- kernel-desktop-latest-4.14.18-1.mga6.i586
- kernel-userspace-headers-4.14.18-1.mga6.i586
- vboxadditions-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6.i586
- vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.i586

VM restarted normally:
$ uname -r
4.14.18-desktop-1.mga6

tested commonly used spplications
no regressions noted

OK for mga6-32 in a vbox VM
Comment 12 Thomas Andrews 2018-02-09 16:31:22 CET
Real hardware: ASRock motherboard, Athlon X2 7750, 8GB RAM, nvidia340 graphics, Atheros wifi.

Two systems on this hardware: One 64-bit Plasma install using the server kernel, and one 32-bit Xfce install with both the desktop and server kernels.

Ran Firefox, each system's file manager, each system's image viewer, and each system's video player. Made some settings changes in the Xfce system.

No problems noted.

As with earlier kernel testing, Bug #22528 is not valid on this hardware. Suspend/resume works as it should.
Comment 13 Len Lawrence 2018-02-09 22:00:03 CET
Updated the desktop kernel packages.
Rebooted to Mate desktop.  nvme disk hardware.

System:    Host: hamal Kernel: 4.14.18-desktop-1.mga6 x86_64
CPU:       Dual core Intel Core i7-7500U (-HT-MCP-) speed/max: 3499/3500 MHz
Machine:   Device: laptop System: Dell product: XPS 13 9360
           Mobo: Dell model: 06CC14 v: A00
Graphics:  Card: Intel HD Graphics 620
           GLX Renderer: Mesa DRI Intel HD Graphics 620 (Kaby Lake GT2)
           GLX Version: 3.0 Mesa 17.3.2
RAM:       15.55 GB
Network:   Card-1: Qualcomm Atheros QCA6174 802.11ac Wireless Network Adapter
           driver: ath10k_pci

Network shares mounted OK.  vlc played video across LAN.  Bluetooth sound working.  Networking and common applications run OK.  Local ruby/tk applications working.

Stress tests ran and terminated properly.
All good so far.
Comment 14 William Kenney 2018-02-09 23:00:14 CET
On real hardware, M6, Plasma, 64-bit

initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current

[root@localhost wilcal]# uname -a
Linux localhost 4.14.16-desktop-1.mga6 #1 SMP Wed Jan 31 20:50:08 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.16-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.6-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.16-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-384.111-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.16-1.mga6.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
        
Using:
Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.

install from update_testing:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current

[root@localhost wilcal]# uname -a
Linux localhost 4.14.18-desktop-1.mga6 #1 SMP Wed Feb 7 23:14:33 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.6-6.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.6-6.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-384.111-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
        
Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Still works as a Vbox client. Boots to a working desktop.

Mageia-6-LiveDVD-GNOME-x86_64-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.

Mageia-6-x86_64-DVD.iso
Installs as a Vbox client. Boots to a working desktop.
Updates then reboots back to a working desktop.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Comment 15 PC LX 2018-02-10 11:42:41 CET
Installed and tested without regressions.

Tested on both HW and VirtualBox VM. Tested for about two days (two boot cicles) of normal usage with some extra testing. No regressions noticed.

System host: Mageia 6, x86_64, Plasma DE, LXQT DE, Intel CPU, nVidia GPU using nvidia340 proprietary driver.
System VirtualBox guest: Mageia 6, x86_64, Plasma DE, OpenBox DE, Intel CPU, using VB guest additions.

$ # host info follows.
$ uname -a
Linux marte 4.14.18-desktop-1.mga6 #1 SMP Wed Feb 7 23:14:33 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | egrep 'kernel|virtualbox|vbox|dkms' | grep -v 4.14.17 | sort
dkms-2.0.19-39.mga6
dkms-minimal-2.0.19-39.mga6
dkms-nvidia340-340.106-1.mga6.nonfree
dkms-virtualbox-5.2.6-1.mga6
kernel-desktop-4.14.18-1.mga6-1-1.mga6
kernel-desktop-devel-4.14.18-1.mga6-1-1.mga6
kernel-desktop-devel-latest-4.14.18-1.mga6
kernel-desktop-latest-4.14.18-1.mga6
kernel-firmware-20170531-1.mga6
kernel-firmware-nonfree-20171220-1.mga6.nonfree
kernel-userspace-headers-4.14.18-1.mga6
virtualbox-5.2.6-1.mga6
virtualbox-doc-5.1.30-1.mga6
virtualbox-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6
virtualbox-kernel-desktop-latest-5.2.6-6.mga6
$ dkms status | grep 4.14.18
nvidia340, 340.106-1.mga6.nonfree, 4.14.18-desktop-1.mga6, x86_64: installed 
virtualbox, 5.2.6-1.mga6, 4.14.18-desktop-1.mga6, x86_64: installed 
virtualbox, 5.2.6-1.mga6, 4.14.18-desktop-1.mga6, x86_64: installed-binary from 4.14.18-desktop-1.mga6
$ lspcidrake
snd_hda_intel   : Intel Corporation|82801JI (ICH10 Family) HD Audio Controller [MULTIMEDIA_AUDIO_DEV]
Card:NVIDIA GeForce 8100 to GeForce 415: NVIDIA Corporation|GT218 [GeForce 210] [DISPLAY_VGA] (rev: a2)
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #2 [SERIAL_USB]                                                                                               
r8169           : Realtek Semiconductor Co., Ltd.|RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller [NETWORK_ETHERNET] (rev: 02)                                                     
shpchp          : Intel Corporation|4 Series Chipset PCI Express Root Port [BRIDGE_PCI] (rev: 03)                                                                                            
lpc_ich         : Intel Corporation|82801JIB (ICH10) LPC Interface Controller [BRIDGE_ISA]                                                                                                   
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #5 [SERIAL_USB]                                                                                               
shpchp          : Intel Corporation|82801JI (ICH10 Family) PCI Express Root Port 1 [BRIDGE_PCI]                                                                                              
pata_jmicron    : JMicron Technology Corp.|JMB368 IDE controller [STORAGE_IDE]                                                                                                               
unknown         : Intel Corporation|82801JI (ICH10 Family) SATA AHCI Controller [STORAGE_SATA]
shpchp          : Intel Corporation|82801JI (ICH10 Family) PCI Express Root Port 3 [BRIDGE_PCI]
ehci_pci        : Intel Corporation|82801JI (ICH10 Family) USB2 EHCI Controller #1 [SERIAL_USB]
ehci_pci        : Intel Corporation|82801JI (ICH10 Family) USB2 EHCI Controller #2 [SERIAL_USB]
snd_hda_intel   : NVIDIA Corporation|High Definition Audio Controller [MULTIMEDIA_AUDIO_DEV] (rev: a1)
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #1 [SERIAL_USB]
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #4 [SERIAL_USB]
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #3 [SERIAL_USB]
uhci_hcd        : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #6 [SERIAL_USB]
shpchp          : Intel Corporation|82801JI (ICH10 Family) PCI Express Port 2 [BRIDGE_PCI]
unknown         : Intel Corporation|4 Series Chipset DRAM Controller [BRIDGE_HOST] (rev: 03)
i2c_i801        : Intel Corporation|82801JI (ICH10 Family) SMBus Controller [SERIAL_SMBUS]
unknown         : Intel Corporation|82801 PCI Bridge [BRIDGE_PCI] (rev: 90)
hub             : Linux 4.14.18-desktop-1.mga6 ehci_hcd|EHCI Host Controller [Hub|Unused|Full speed (or root) hub]
usb_storage     : Generic|Mass Storage Device [Mass Storage|SCSI|Bulk-Only]
hub             : Linux 4.14.18-desktop-1.mga6 ehci_hcd|EHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hub             : Genesys Logic, Inc.|USB2.0 Hub [Hub|Unused|Full speed (or root) hub]
usb_storage     : Prolific Technology Inc.|Mass Storage Device [Mass Storage|SCSI|Bulk-Only]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
Mouse:evdev     : Logitech|USB Receiver [Human Interface Device|Boot Interface Subclass|Keyboard]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hub             : Linux 4.14.18-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub]
hid_logitech    : Logitech USB Receiver
hid_logitech    : Logitech USB Receiver


$ # VirtualBox guest info follows.
$ uname -a
Linux localhost 4.14.18-desktop-1.mga6 #1 SMP Wed Feb 7 23:14:33 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | egrep 'kernel|vbox|virtualbox|dkms' | sort
dkms-minimal-2.0.19-39.mga6
kernel-desktop-4.14.15-3.mga6-1-1.mga6
kernel-desktop-4.14.18-1.mga6-1-1.mga6
kernel-desktop-latest-4.14.18-1.mga6
kernel-firmware-20170531-1.mga6
kernel-firmware-nonfree-20171220-1.mga6.nonfree
vboxadditions-kernel-4.14.15-desktop-3.mga6-5.2.6-3.mga6
vboxadditions-kernel-4.14.18-desktop-1.mga6-5.2.6-6.mga6
vboxadditions-kernel-desktop-latest-5.2.6-6.mga6
virtualbox-guest-additions-5.2.6-1.mga6
x11-driver-video-vboxvideo-5.2.6-1.mga6

CC: (none) => mageia

Comment 16 Len Lawrence 2018-02-10 21:09:39 CET
Installed the desktop kernel.
Rebooted to Mate desktop.

System:    Host: markab Kernel: 4.14.18-desktop-1.mga6 x86_64
CPU:       Quad core Intel Core i7-5700HQ (-HT-MCP-) speed/max: 2697/3500 MHz
Machine:   Device: laptop System: GIGABYTE product: X5
Graphics:  Card-1: NVIDIA GM204M [GeForce GTX 965M]
           Card-2: NVIDIA GM204M [GeForce GTX 965M]
           GLX Version: 4.5.0 NVIDIA 384.111
RAM:       15.62 GB
Network:   Card-2: Intel Wireless 7265 driver: iwlwifi

Nothing of note to report apart from the desktop weather icon not working.  Hardware stress tests completed.
System recovered from suspend when laptop lid was closed and opened.
Comment 17 Len Lawrence 2018-02-10 23:05:03 CET
Installed the server kernel.
Rebooted to Mate desktop.

System:    Host: markab Kernel: 4.14.18-server-1.mga6 x86_64
CPU:       Quad core Intel Core i7-5700HQ (-HT-MCP-) speed/max: 2697/3500 MHz
Machine:   Device: laptop System: GIGABYTE product: X5
Graphics:  Card-1: NVIDIA GM204M [GeForce GTX 965M]
           Card-2: NVIDIA GM204M [GeForce GTX 965M]
           GLX Version: 4.5.0 NVIDIA 384.111
RAM:       15.62 GB
Network:   Card-2: Intel Wireless 7265 driver: iwlwifi

Stress tests ran fine.  wifi and network shares working.
Network video streaming OK and bluetooth sound.  Set up a wifi printer with hplip and printed a document from LibreOffice.  Weather icon works.  Laptop suspends and recovers when lid is closed and opened.
Comment 18 Len Lawrence 2018-02-11 08:16:12 CET
Installed desktop kernel packages.

Legacy boot.
System:    Host: juza Kernel: 4.14.18-desktop-1.mga6 x86_64 (64 bit)
CPU:       Quad core Intel Core i7-3630QM (-HT-MCP-)
Machine:   Device: laptop System: LENOVO product: 9541 v: Lenovo IdeaPad Y500
Graphics:  Card: NVIDIA GK107M [GeForce GT 650M]
           GLX Version: 4.5.0 NVIDIA 384.111
RAM:       7.74 GB
Network:   Card-2: Intel Centrino Wireless-N 2230 driver: iwlwifi
	   
No problem with hardware tests.  wifi networking OK.  NFS shares mounted.
All is normal on the desktop.
Comment 19 Thomas Backlund 2018-02-11 17:43:07 CET
Advisory, added to svn:

type: security
subject: Updated kernel packages fix security vulnerabilities
CVE:
 - CVE-2017-5715
 - CVE-2017-5753
src:
  6:
   core:
     - kernel-4.14.18-1.mga6
     - kernel-userspace-headers-4.14.18-1.mga6
     - kmod-vboxadditions-5.2.6-6.mga6
     - kmod-virtualbox-5.2.6-6.mga6
     - kmod-xtables-addons-2.13-16.mga6
     - wireguard-tools-0.0.20180202-1.mga6
description: |
  This kernel update is based on the upstream 4.14.18 and and adds some
  support for mitigating  Spectre, variant 1 (CVE-2017-5753) and as it is
  built with the retpoline-aware gcc-5.5.0-1.mga6, it now provides full
  retpoline mitigation for Spectre, variant 2 (CVE-2017-5715).

  WireGuard has been updated to 0.0.20180202

  This update also fixes the rtl8812au driver that got broken/missing in
  the upgrade to 4.14 series kernels (mga#22524).

  For other fixes in this update, read the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=22533
 - https://bugs.mageia.org/show_bug.cgi?id=22524
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.17
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.18

Keywords: (none) => advisory

Comment 20 Thomas Backlund 2018-02-11 19:29:05 CET
Validating as good enough as its been tested on several systems, both arches and on vbox...

Whiteboard: (none) => MGA6-64-OK, MGA6-32-OK
Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 21 Mageia Robot 2018-02-11 19:43:40 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0125.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.