* Security fixes from upstream XSAs:
XSA-252 CVE-2018-7540
XSA-255 CVE-2018-7541
XSA-256 CVE-2018-7542
The upstream BTI changes from XSA-254 (Spectre v2 mitigation)
are *not* included. They are currently failing in upstream CI.
* init scripts: Do not kill per-domain qemu processes. Closes:#879751.
* Install Meltdown READMEs on all architectures. Closes:#890488.
* Ship xen-diag (by cherry-picking the appropriate commits from
upstream). This can help with diagnosis of #880554.