SDLab

SDLab
SDLab.org::Adminな脳み
ラベル XenServer運用 の投稿を表示しています。 すべての投稿を表示
ラベル XenServer運用 の投稿を表示しています。 すべての投稿を表示

2015年8月20日木曜日

Vulnerability in Citrix XenServer Could Result in Information Disclosure


Vulnerability in Citrix XenServer Could Result in Information Disclosure

落ち着かないHVMの話。
パッチも出てたので更新しておきました。
XenServer6.2 SP1 のパッチリスト (2015/8/20 時点)

2015年8月15日土曜日

pygrub と eliloader

なんだろね。これ。

XenServer5.6SP2 のPVをXVAにExportして、
XenServer6.5SP1 にIMPORTしたら、
「Error 13: Invalid or unsupported executable format」
とエラーになり起動しない。

xe vm-param-list uuid=***************
で確認したら、
PV-bootloader ( RW): eliloader

え?pygrubがeliloaderになってる。
XenServer6.2SP1 にも同じXVAをIMPORTしたら同じ現象だった。
XenServer5.6SP2 からのEXPORTに問題があったっぽいけど・・・なんだろうね。

xe vm-param-set uuid=*************** PV-bootloader=pygrub
で無事に起動。

2015年7月28日火曜日

Citrix XenServer Security Update for CVE-2015-5154

Citrix XenServer Security Update for CVE-2015-5154

  • CVE-2015-5154: QEMU heap overflow flaw while processing certain ATAPI commands
Customers that only have PV guests deployed are not at risk.
PV Guestには影響は無いようです。

Patchはでてます。


Hotfix XS65ESP1008 - For XenServer 6.5.0 Service Pack 1

Hotfix XS62ESP1030 - For XenServer 6.2.0 Service Pack 1


2015年7月21日火曜日

This reduces the VM downtime

CP-11841: 
vm-migrate downtime: plug the VIFs of the new domain before suspending the old domain
https://github.com/xapi-project/xenopsd/pull/205

This reduces the VM downtime (when both old and new domains are paused) in 0.3s
for each VIF connected to the VM.

ダウンタイムの削減。

2015年5月20日水曜日

XenServer6.5 SP1 のパッチリスト (2016/2/24 時点)

現状のXenServer6.5 SP1のパッチリスト

Recommended Updates for XenServer 6.x Hotfixes
http://support.citrix.com/article/CTX138115

  • XenServer 6.5.0 SP1 適用
  • Reboot
  • Hotfix XS65ESP1001 (XenCenter)
  • Hotfix XS65ESP1012
  • Hotfix XS65ESP1018 (XenTools)
  • Hotfix XS65ESP1021 (KernelとSM/blktap)
  • Hotfix XS65ESP1022 (OpenSSL)
  • Hotfix XS65ESP1023 (SecurityFix)
  • Reboot


    すごく久しぶりに更新。推奨サイトはかなり整理されていい感じ。

    --

    Hotfix XS65ESP1001 - For XenServer 6.5.0 SP1
    http://support.citrix.com/article/CTX142447

    最近お決まりの一発目は XenCenterの更新

    Hotfix XS65ESP1002 - For XenServer 6.5.0 SP1
    https://support.citrix.com/article/CTX142483
    VENOM対応

    Hotfix XS65ESP1003 - For XenServer 6.5.0 Service Pack 1
    http://support.citrix.com/article/CTX142583
    Xentools更新(Windows)

    Hotfix XS65ESP1004- For XenServer 6.5.0 Service Pack 1
    https://support.citrix.com/article/CTX142538
    PCIまわりの修正

    Hotfix XS65E010- For XenServer 6.5.0
    http://support.citrix.com/article/CTX142537
    Security Fix

    Hotfix XS65ESP1005 - For XenServer 6.5.0 Service Pack 1
    http://support.citrix.com/article/CTX201514
    HostをCrashさせる不具合を修正
    ・VBD をplug/unplug
    ・Netback
    ・Serial Console
    ・受信したNetworkTraffice

    Hotfix XS65ESP1008 
    https://support.citrix.com/article/CTX201637
    Security Update。QEMUのATAPI関連。

    Hotfix XS65E013
    http://support.citrix.com/article/CTX201636
    CVE-2015-5154: QEMU heap overflow flaw while processing certain ATAPI commands

    Hotfix XS65ESP1009
    http://support.citrix.com/article/CTX201741
    CVE-2015-5165: QEMU leak of uninitialized heap memory in rtl8139 device model

    Hotfix XS65ESP1010
    http://support.citrix.com/article/CTX201974
    Xentools更新(Windows10とWindows向け)

    Hotfix XS65ESP1011
    http://support.citrix.com/article/CTX202074
    Intel系でPCIパススルーとかGPUパススルー使うとクラッシュする問題のFIXや
    WinのDHCP Serverを使ったときの問題やhvmloaderの問題修正など。

    Hotfix XS65ESP1012
    http://support.citrix.com/article/CTX202481
    主にxapiの不具合修正

    Hotfix XS65ESP1014
    http://support.citrix.com/article/CTX202439
    PVからHOSTをクラッシュできる脆弱性の修正など

    Hotfix XS65ESP1016
    https://support.citrix.com/article/CTX202619
    HVMからPVをクラッシュできる脆弱性の修正など

    Hotfix XS65ESP1018 
    http://support.citrix.com/article/CTX205190
    XenToolsの更新。主にWindows向け。
    (Includes XS65ESP1003 and XS65ESP1010)

    Hotfix XS65ESP1021
    http://support.citrix.com/article/CTX204053
    KernelとSM/blktapの更新。
    SoftwareRAIDへの対応。
    ShutdownしたVMのVIFのnetback(ホスト側)が残ってしまう不具合修正
    (Includes XS65ESP1005 and XS65ESP1013)

    Hotfix XS65ESP1022
    http://support.citrix.com/article/CTX205228
    * OpenSSLの更新

    Hotfix XS65ESP1023
    http://support.citrix.com/article/CTX205355
    セキュリティFIX:CVE-2016-1571 (Medium): VMX: intercept issue with INVLPG on non-canonical address (IntelCPUのみ)
    (Includes XS65E009, XS65E010, XS65E013, XS65E014, XS65E015, XS65E017, XS65E018, 
    XS65ESP1002, XS65ESP1004, XS65ESP1008, XS65ESP1009 , XS65ESP1011, XS65ESP1014, XS65ESP1016, XS65ESP1019, XS65ESP1020)


    2015年3月11日水曜日

    Windows のxentoolsの綺麗なアンインストールの仕方

    みんなが困っている Windows のXenTools
    当然Citrixからの情報なんて当てにならないのは既知の事実
    例えば、これ。

    お勧めしない情報)Unable to Install or Upgrade XenTools for Windows Virtual

    https://support.citrix.com/article/CTX139031

    信じてやると、期待を裏切らず、炎上。

    というわけで、フォーラムの投稿にフォローをいれてまとめました。
    XenServer 6.2 SP1 Tools
    http://discussions.citrix.com/topic/345962-xenserver-62-sp1-tools/page-2#entry1789111

    STEP1: Booted VM into Safe Mode


    1. セーフモードで起動
      ・msconfig のブートタブから、ブートオプション、セーフブート、最小 で適用、OK。
      ・Reboot(1回目)
    2. コントロールパネルから プログラムと機能を開き、次を「アンインストール」
      ・Windows Driver Package - Citrix Systems Inc. (xenbus)
      ・Windows Driver Package - Citrix Systems Inc. (xennet)
      ・Windows Driver Package - Citrix Systems Inc. (xenvif)
      ・Windows Driver Package - Citrix Systems Inc. (xeniface)
      ・Windows Driver Package - Citrix Systems Inc. (xenvbd)
    3. msconfig のブートタブから、ブートオプション、セーフブートのチェックを外し(正常ブート)で適用、OK。
    4. Reboot(2回目)

    STEP2: 通常起動でアンインストール


    1. コントロールパネルから プログラムと機能(プログラムのアンインストール)を開き、次を「アンインストール」
      ・Citrix Xen Windows x64 PV Drivers
      ・Citrix XenServer Tools Installer
      ・Citrix XenServer VSS Provider
      ・Citrix XenServer Windows Guest Agent
    2. Reboot(3回目)


    以上でキレイにUninstallできます!

    あとは、初期と同様にXentoolsをインストールすればOK!
    なお、この手順でやると、多分5-6回の再起動が必要です。


    <2015/5/1 追記>
    XS62ESP1020 がでた
    http://support.citrix.com/article/CTX142219
    上記の問題の修正らしい。

    2015年3月6日金曜日

    XenServer 5.6 SP2 のパッチ適用

    あてる必要があったので、MEMO

    対象と順番はこれで平気かな。

    xe patch-upload file-name=XS56ESP2001.xsupdate  > XS56SP2-PATCH-UUID
    xe patch-upload file-name=XS56ESP2003.xsupdate >> XS56SP2-PATCH-UUID
    xe patch-upload file-name=XS56ESP2011.xsupdate >> XS56SP2-PATCH-UUID
    xe patch-upload file-name=XS56ESP2023.xsupdate >> XS56SP2-PATCH-UUID
    xe patch-upload file-name=XS56ESP2025.xsupdate >> XS56SP2-PATCH-UUID
    xe patch-upload file-name=XS56ESP2034.xsupdate >> XS56SP2-PATCH-UUID


    上記で作った XS56SP2-PATCH-UUID にはUUIDがあてる順番に入ってるので、

            for PATCHID in `cat XS56SP2-PATCH-UUID`
            do
                echo "HOST: ${HOSTUUID} / PATCH: ${PATCHID}"
                xe patch-apply host-uuid=${HOSTUUID} uuid=${PATCHID}
            done

    ってな感じであててけば楽。
    # 前後は自分で書いてね。

    XenServer6.5 のパッチリスト (2015/5/20時点)

    <XenServer6.5SP1 がリリースされています>

    現状のXenServer6.5 のパッチリスト

    Recommended Updates for XenServer 6.x Hotfixes
    http://support.citrix.com/article/CTX138115
    には記述が無いが、
    現状は

    • Hotfix XS65E002
    • Hotfix XS65E003
    • Hotfix XS65E005
    • Hotfix XS65E007
    • Hotfix XS65E008
    • Hotfix XS65E009

    を適用し、Rebootでいいと思う。

    --

    Hotfix XS65E001 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142060

    最近お決まりの一発目は XenCenterの更新

    Hotfix XS65E002 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142059

    Windows向けXenServer Toolsの修正
    ※このPatchをあてた後、Windows VMのXenServer toolsはアップグレードを推奨

    Hotfix XS65E003 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142061

    glibcだけの修正

    Hotfix XS65E005 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142141

    Space reclamation(StorageTabで見るとReclaim freed spaceと表示される)を使った2TB以上のLUNがデータ不正になる件の修正。

    Hotfix XS65E006 - For XenServer 6.5.0
    https://support.citrix.com/article/CTX142147
    セキュリティアップデート(x86)

    Hotfix XS65E007 - For XenServer 6.5.0
    https://support.citrix.com/article/CTX142273
    セキュリティアップデート(QEMU)

    Hotfix XS65E008 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142266
    GPUパススルーの不具合修正

    Hotfix XS65E009 - For XenServer 6.5.0
    VENOM


    Hotfix XS62ESP1017 - For XenServer 6.2.0 Service Pack 1

    Hotfix XS62ESP1017 - For XenServer 6.2.0 Service Pack 1
    http://support.citrix.com/article/CTX142012

    本文を読んでもらえば最後に書いてあるように、glibcのパッケージの更新のみ。
    これだと、現時点ではあてるメリットは薄いと思ってる。

    XenServer 6.2 SP1 のパッチのまとめはこっち。

    XenServer6.2 SP1 のパッチリスト (2015/3/6時点)http://mada0833.blogspot.jp/2014/04/XenServer62SP1PatchList.html

    2015年2月23日月曜日

    Why we use OPAM for XenServer development


    Why we use OPAM for XenServer development
    https://opam.ocaml.org/blog/opam-in-xenserver/


    • manages clusters of Xen hosts with shared storage and networking
    • allows running VMs to be migrated between hosts (with or without storage) with minimal downtime
    • automatically restarts VMs after host failure (High Availability)
    • allows cross-site Disaster Recovery
    • simplifies maintainence through Rolling Pool Upgrade
    • collects performance statistics for historical analysis and for alerting
    • has a full-featured XML-RPC based API, used by clients such as XenCenter, Xen Orchestra, OpenStack and CloudStack


    xapi のインストール方法(CentOS6への)なので、メモっておきます。

    2015年2月20日金曜日

    Conver XVA to VHD

    Re: [xs-devel] covert xva to img
    https://lists.xenserver.org/sympa/arc/xs-devel/2015-02/msg00078.html

    Try something like (on 6.5 and later)
    $ xe vdi-export uuid=… filename=foo.vhd format=vhd ?progress

    XenServer6.5以降ではできるっぽい。試してないけど。

    2015年2月13日金曜日

    Hotfix XS65E001 - For XenServer 6.5.0

    Hotfix XS65E001 - For XenServer 6.5.0
    http://support.citrix.com/article/CTX142060

    XenCenterの修正。
    GPUタブの修正とかvGPU設定とか、Rolling Pool Upgrade時のStaticIPが失敗するとか、WLBの修正とか。

    2015年1月29日木曜日

    XenServer 6.5 と Software RAID

    Software RAID (mdadm) on XenServer 6.5 unexpected failure
    http://discussions.citrix.com/topic/360943-software-raid-mdadm-on-xenserver-65-unexpected-failure/

    XenServer 6.5 do not load soft raid kernel modules on boot. (See comments by Roland Monday on this article).

    My solution is:
    1. Create file /etc/sysconfig/modules/raid.modules with needed modules
    # echo "modprobe raid1" > /etc/sysconfig/modules/raid.modules
    you can add lines for another raid level (raid0 or raid10 for example)

    2. Make this file executable
    # chmod +x /etc/sysconfig/modules/raid.modules

    3. Reboot.

    PS: I do not know will this changes survive after installing patches

    読んでの通り、XS6.5は ソフトウェアRAID のKernel ModuleをBoot時に読み込まないので、
    読み込んでから、mdadm --create しろという話し。

    glibc GHOST Vulnerability と XenServer

    Citrix Security Advisory for glibc GHOST Vulnerability (CVE-2015-0235)
    http://support.citrix.com/article/CTX200391

    Citrix XenServer: Analysis into the impact of this issue on XenServer is in progress. XenServer does include a vulnerable version of glibc but at present there is no known route by which a guest virtual machine would be able to invoke the vulnerable functionality through the hypervisor interface. Analysis of this is still in progress and this section will be updated when additional information is available.

    調査中だけど、まぁ大丈夫じゃね?って感じ。
    なお、私的には下記に同意。

    Linuxに存在する脆弱性「GHOST」、システム管理者は落ち着いて対処を
    http://blog.trendmicro.co.jp/archives/10818

    最後に、この脆弱性が対象とする関数「gethostbyname*()」はすでに古いものとなっています。これらの関数は IPv6アドレスに対応していないため、多くの新しいアプリケーションでは、この脆弱な関数「gethostbyname*()」ではなく、IPv6 をサポートする関数「getaddrinfo()」を使用しているものと考えられます。
    以上を考慮すると、「GHOST」を狙った実際の攻撃による危険性は、「Shellshock」や「Heartbleed」などの脆弱性と比較すると低いものになっています。

    下記のメジャーどころは影響受けない。
    Re: Qualys Security Advisory CVE-2015-0235 - GHOST: glibc gethostbyname buffer overflow
    http://seclists.org/oss-sec/2015/q1/283

    apache, cups, dovecot, gnupg, isc-dhcp, lighttpd, mariadb/mysql,
    nfs-utils, nginx, nodejs, openldap, openssh, postfix, proftpd,
    pure-ftpd, rsyslog, samba, sendmail, sysklogd, syslog-ng, tcp_wrappers,
    vsftpd, xinetd.

    でも古いのは影響受ける場合がある。
    http://www.openwall.com/lists/oss-security/2015/01/27/9
    ProcmailとかEximとかは影響をうける。

    2015年1月9日金曜日

    Hotfix XS62ESP1016 - For XenServer 6.2.0 Service Pack 1

    Hotfix XS62ESP1016 - For XenServer 6.2.0 Service Pack 1
    http://support.citrix.com/article/CTX141779

    新機能:

    • Supports the firmware of Dell EqualLogic 7.x arrays with Integrated StorageLink (iSL).
    • Contains improvements for generating crash dump files.


    iSLのサポートって無くなってた気がするが、復活したの?よくしらないけど。

    Hotfix:

    • Migration時の動作や、SM関連の修正。お、早速試してる。


    含まれるPATCH:

    • XS62ESP1002
    • XS62ESP1004
    • XS62ESP1008
    • XS62ESP1011
    • XS62ESP1013
    • XS62ESP1015


    あて方は、XS62ESP1015の置き換えていいと思う。

    2014年12月3日水曜日

    Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1

    Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1
    https://support.citrix.com/article/CTX141717

    含まれるFix
    This hotfix also includes the following previously released hotfixes:
    CTX140052 -  Hotfix XS62E014 - For XenServer 6.2.0
    CTX140051 -  Hotfix XS62ESP1002 - For XenServer 6.2.0 Service Pack 1
    CTX140417 -  Hotfix XS62ESP1004 - For XenServer 6.2.0 Service Pack 1
    CTX141036 -  Hotfix XS62ESP1008 - For XenServer 6.2.0 Service Pack 1
    CTX141472 -  Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1
    CTX141480 -  Hotfix XS62ESP1013 - For XenServer 6.2.0 Service Pack 1

    あて方は、XS62ESP015には、Kernelが含まれていないため、
    Recommended Updates for XenServer 6.x Hotfixes
    のXS62ESP1013の置き換えと考えてよさそうだ。

    XS62ESP1009は最後かぁ・・・

    2014年10月14日火曜日

    Hotfix XS62ESP1013 - For XenServer 6.2.0 Service Pack 1

    Hotfix XS62ESP1013 - For XenServer 6.2.0 Service Pack 1

    https://support.citrix.com/article/CTX141480

    下記の不具合修正
    http://support.citrix.com/article/CTX200218
    CVE-2014-7155 (High): Missing privilege level checks in x86 HLT, LGDT, LIDT, and LMSW
    CVE-2014-7156 (Medium): Missing privilege level checks in x86 emulation of software interrupts
    CVE-2014-7188 (High): Improper MSR range used for x2APIC emulation


    下記が含まれる
    XS62ESP1002
    XS62ESP1004
    XS62ESP1008
    XS62ESP1011

    XS62ESP1014 - Bash Update

    Hotfix XS62ESP1014 - For XenServer 6.2.0 Service Pack 1


    bash-3.2-33.el5_11.4.i386.rpm
    BashのUpdateのみ。
    Restartは不要。

    2014年10月1日水曜日

    Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1

    Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1



    私的にはこの辺かな。
    The option Restore Virtual Machine Metadata in xsconsole fails to restore VDIs on the storage repositories (SRs). VDIs are restored if the SRs contain the backup of the pool metadata.
    When Linux bridge is used as the network stack, generic receive offload (GRO) does not always work on VLANs.

    なお、XS62ESP1002 / XS62ESP1004 / XS62ESP1008 が含まれる。

    最近Blogの更新ができません。
    だれかうちでXenServerの技術者しませんか?

    2014年9月11日木曜日

    XenServer6.2 パッチ当て XS62ESP1008まで

    Recommended Updates for XenServer 6.x Hotfixes
    http://support.citrix.com/article/CTX138115

    XenServer6.2だと、

    1. XenCenterを最新(XS62SP1のXenCenterを利用)にして、
    2. SP1をあてて、
    3. Reboot。
    4. 起動後、XS62ESP1003、XS62ESP1008、XS62ESP1005の順であてて、
    5. 必要ならば、XS62ESP1005のドライバを入れて、
    6. Reboot。

    という手順。

    なぜ、XS62ESP1008をXS62ESP1005の前かというと、
    XS62ESP1008のKernelが腐ってる問題を含んでいるから。

    もし、XS62ESP1009をあてるなら、
    XS62ESP1005の代わりにあてれば良さそう。
    XS62ESP1009について書かれてないのはなぜだろう?
    XS62ESP1008と同じように、Kernelに問題があったりして。
    うちのは動いてるけど。XS62ESP1009のKernel。