Upstream commit [1]
This will bump the need for libseccomp to >=2.2 which has an update to the configure script [2].
Furthermore I think that the old (whitelist) approach might be able to trigger issues if extended to the other threads (which would be correct but might regress people).
Therefore again pre Bionic qemu needs double checks and consideration.
I'm not entirely sure on severity/priority and implications I'd leave X/T for the consideration of the security Team.
I think we can and should fix Cosmic for sure and I'd start on that now.
I have another Qemu SRU Prepped that I could bundle to unify uploads and testing.
I'll spawn tasks according to that assigning clearly who would work on what.
Upstream commit [1]
This will bump the need for libseccomp to >=2.2 which has an update to the configure script [2].
Furthermore I think that the old (whitelist) approach might be able to trigger issues if extended to the other threads (which would be correct but might regress people).
Therefore again pre Bionic qemu needs double checks and consideration.
I'm not entirely sure on severity/priority and implications I'd leave X/T for the consideration of the security Team.
I think we can and should fix Cosmic for sure and I'd start on that now.
I have another Qemu SRU Prepped that I could bundle to unify uploads and testing.
I'll spawn tasks according to that assigning clearly who would work on what.
[1]: https:/ /git.qemu. org/?p= qemu.git; a=commit; h=70dfabeaa79ba 4d7a3b699abe1a0 47c8012db114 /git.qemu. org/?p= qemu.git; a=commit; h=d0699bd37c480 67cffbd80383172 efc29da6d2f9
[2]: https:/