From 990f1c2c0e716bbae2b346fc9a922d4b36dbb726 Mon Sep 17 00:00:00 2001 From: Alex Nahas Date: Sat, 3 Oct 2026 12:28:37 -0700 Subject: [PATCH] Update default Cloud Hypervisor to v51.2 v49.0 and v51.1 are affected by CVE-2026-45782. Embed v51.2 and use it for new instances; keep older versions so existing snapshots restore. --- .github/workflows/test.yml | 2 +- Makefile | 10 ++++++++-- lib/hypervisor/cloudhypervisor/cloudhypervisor.go | 2 +- lib/hypervisor/cloudhypervisor/register_linux_test.go | 10 ++++++++++ lib/vmm/README.md | 6 +++++- lib/vmm/binaries_darwin.go | 3 ++- lib/vmm/binaries_linux.go | 7 +++++-- lib/vmm/client_test.go | 2 ++ 8 files changed, 34 insertions(+), 8 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 24e199706..ac7f89b91 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -187,7 +187,7 @@ jobs: GH_TOKEN: ${{ github.token }} run: | set -euo pipefail - for version in v49.0 v51.1; do + for version in v49.0 v51.1 v51.2; do for architecture in x86_64 aarch64; do if [ "$architecture" = "x86_64" ]; then asset="cloud-hypervisor-static" diff --git a/Makefile b/Makefile index 99550631f..2cfae9ab0 100644 --- a/Makefile +++ b/Makefile @@ -35,11 +35,12 @@ $(XCADDY): | $(BIN_DIR) install-tools: $(OAPI_CODEGEN) $(AIR) $(WIRE) $(XCADDY) -# Download Cloud Hypervisor binaries (both v49.0 and v51.1 for backwards-compatible upgrades) +# Download Cloud Hypervisor binaries (v49.0, v51.1 and v51.2 for backwards-compatible upgrades) download-ch-binaries: @echo "Downloading Cloud Hypervisor binaries..." @mkdir -p lib/vmm/binaries/cloud-hypervisor/v49.0/{x86_64,aarch64} @mkdir -p lib/vmm/binaries/cloud-hypervisor/v51.1/{x86_64,aarch64} + @mkdir -p lib/vmm/binaries/cloud-hypervisor/v51.2/{x86_64,aarch64} @echo "Downloading v49.0..." @curl -L -o lib/vmm/binaries/cloud-hypervisor/v49.0/x86_64/cloud-hypervisor \ https://github.com/cloud-hypervisor/cloud-hypervisor/releases/download/v49.0/cloud-hypervisor-static @@ -50,6 +51,11 @@ download-ch-binaries: https://github.com/cloud-hypervisor/cloud-hypervisor/releases/download/v51.1/cloud-hypervisor-static @curl -L -o lib/vmm/binaries/cloud-hypervisor/v51.1/aarch64/cloud-hypervisor \ https://github.com/cloud-hypervisor/cloud-hypervisor/releases/download/v51.1/cloud-hypervisor-static-aarch64 + @echo "Downloading v51.2..." + @curl -L -o lib/vmm/binaries/cloud-hypervisor/v51.2/x86_64/cloud-hypervisor \ + https://github.com/cloud-hypervisor/cloud-hypervisor/releases/download/v51.2/cloud-hypervisor-static + @curl -L -o lib/vmm/binaries/cloud-hypervisor/v51.2/aarch64/cloud-hypervisor \ + https://github.com/cloud-hypervisor/cloud-hypervisor/releases/download/v51.2/cloud-hypervisor-static-aarch64 @chmod +x lib/vmm/binaries/cloud-hypervisor/v*/*/cloud-hypervisor @echo "Binaries downloaded successfully" @@ -177,7 +183,7 @@ ensure-ch-binaries: echo "Unsupported architecture: $$ARCH"; exit 1; \ fi; \ NEEDS_DOWNLOAD=0; \ - for CH_VERSION in v49.0 v51.1; do \ + for CH_VERSION in v49.0 v51.1 v51.2; do \ CH_BIN=lib/vmm/binaries/cloud-hypervisor/$$CH_VERSION/$$CH_ARCH/cloud-hypervisor; \ if [ ! -f "$$CH_BIN" ]; then \ echo "Cloud Hypervisor binary not found: $$CH_BIN"; \ diff --git a/lib/hypervisor/cloudhypervisor/cloudhypervisor.go b/lib/hypervisor/cloudhypervisor/cloudhypervisor.go index 6b3b4a781..09da0ba15 100644 --- a/lib/hypervisor/cloudhypervisor/cloudhypervisor.go +++ b/lib/hypervisor/cloudhypervisor/cloudhypervisor.go @@ -73,7 +73,7 @@ func CapabilitiesForVersion(v vmm.CHVersion) hypervisor.Capabilities { SupportsSnapshotBaseReuse: false, } switch v { - case vmm.V51_1: + case vmm.V51_1, vmm.V51_2: caps.SupportsDiskResize = true } return caps diff --git a/lib/hypervisor/cloudhypervisor/register_linux_test.go b/lib/hypervisor/cloudhypervisor/register_linux_test.go index 6d2189588..368ee9fc7 100644 --- a/lib/hypervisor/cloudhypervisor/register_linux_test.go +++ b/lib/hypervisor/cloudhypervisor/register_linux_test.go @@ -51,3 +51,13 @@ func TestCapabilitiesAdvertiseForkOnEveryVersion(t *testing.T) { require.True(t, CapabilitiesForVersion(v).SupportsFork, "version %s", v) } } + +// TestCapabilitiesAdvertiseDiskResizeOnV51 pins live disk resize for every +// v51 release, including the v51.2 default used for new instances. +func TestCapabilitiesAdvertiseDiskResizeOnV51(t *testing.T) { + t.Parallel() + require.Equal(t, vmm.V51_2, vmm.DefaultVersion) + for _, v := range []vmm.CHVersion{vmm.V51_1, vmm.V51_2} { + require.True(t, CapabilitiesForVersion(v).SupportsDiskResize, "version %s", v) + } +} diff --git a/lib/vmm/README.md b/lib/vmm/README.md index f8b7e23c8..741d2e3af 100644 --- a/lib/vmm/README.md +++ b/lib/vmm/README.md @@ -78,7 +78,10 @@ lib/vmm/ │ ├── v49.0/ │ │ ├── x86_64/cloud-hypervisor │ │ └── aarch64/cloud-hypervisor -│ └── v51.1/ +│ ├── v51.1/ +│ │ ├── x86_64/cloud-hypervisor +│ │ └── aarch64/cloud-hypervisor +│ └── v51.2/ │ ├── x86_64/cloud-hypervisor │ └── aarch64/cloud-hypervisor └── client_test.go # Tests with real Cloud Hypervisor @@ -88,6 +91,7 @@ lib/vmm/ - Cloud Hypervisor v49.0 (API v0.3.0) - Cloud Hypervisor v51.1 (API v0.3.0) +- Cloud Hypervisor v51.2 (API v0.3.0) Cloud Hypervisor versions may update frequently while the API updates less frequently. All embedded versions currently share the same API spec. diff --git a/lib/vmm/binaries_darwin.go b/lib/vmm/binaries_darwin.go index 5c46eaf52..2d5e07512 100644 --- a/lib/vmm/binaries_darwin.go +++ b/lib/vmm/binaries_darwin.go @@ -14,9 +14,10 @@ type CHVersion string const ( V49_0 CHVersion = "v49.0" V51_1 CHVersion = "v51.1" + V51_2 CHVersion = "v51.2" ) -const DefaultVersion = V51_1 +const DefaultVersion = V51_2 // SupportedVersions lists supported Cloud Hypervisor versions. // On macOS, Cloud Hypervisor is not supported (use vz instead). diff --git a/lib/vmm/binaries_linux.go b/lib/vmm/binaries_linux.go index 6856b7898..ef423e2a3 100644 --- a/lib/vmm/binaries_linux.go +++ b/lib/vmm/binaries_linux.go @@ -17,6 +17,8 @@ import ( //go:embed binaries/cloud-hypervisor/v49.0/aarch64/cloud-hypervisor //go:embed binaries/cloud-hypervisor/v51.1/x86_64/cloud-hypervisor //go:embed binaries/cloud-hypervisor/v51.1/aarch64/cloud-hypervisor +//go:embed binaries/cloud-hypervisor/v51.2/x86_64/cloud-hypervisor +//go:embed binaries/cloud-hypervisor/v51.2/aarch64/cloud-hypervisor var binaryFS embed.FS type CHVersion string @@ -24,11 +26,12 @@ type CHVersion string const ( V49_0 CHVersion = "v49.0" V51_1 CHVersion = "v51.1" + V51_2 CHVersion = "v51.2" ) -const DefaultVersion = V51_1 +const DefaultVersion = V51_2 -var SupportedVersions = []CHVersion{V49_0, V51_1} +var SupportedVersions = []CHVersion{V49_0, V51_1, V51_2} // ExtractBinary extracts the embedded Cloud Hypervisor binary to the data directory func ExtractBinary(p *paths.Paths, version CHVersion) (string, error) { diff --git a/lib/vmm/client_test.go b/lib/vmm/client_test.go index fc92b7b53..d9165321a 100644 --- a/lib/vmm/client_test.go +++ b/lib/vmm/client_test.go @@ -38,6 +38,7 @@ func TestExtractBinary(t *testing.T) { func TestIsVersionSupported(t *testing.T) { assert.True(t, IsVersionSupported(V49_0)) assert.True(t, IsVersionSupported(V51_1)) + assert.True(t, IsVersionSupported(V51_2)) assert.False(t, IsVersionSupported("v1.0")) } @@ -120,6 +121,7 @@ func TestMultipleVersions(t *testing.T) { }{ {"v49.0", V49_0}, {"v51.1", V51_1}, + {"v51.2", V51_2}, } for _, tt := range tests {