<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src-test2/lib/libc, branch releng/9.3</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src-test2/atom?h=releng%2F9.3</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src-test2/atom?h=releng%2F9.3'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/'/>
<updated>2016-12-07T23:35:15Z</updated>
<entry>
<title>Merge r309688: address regressions in SA-16:37.libc.</title>
<updated>2016-12-07T23:35:15Z</updated>
<author>
<name>Gleb Smirnoff</name>
<email>glebius@FreeBSD.org</email>
</author>
<published>2016-12-07T23:35:15Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=8c7ff71d356bdceffa6cd5b5017c65d0d63d9abc'/>
<id>urn:sha1:8c7ff71d356bdceffa6cd5b5017c65d0d63d9abc</id>
<content type='text'>
PR:		215105
Submitted by:	&lt;jtd2004a sbcglobal.net&gt;
Approved by:	so
</content>
</entry>
<entry>
<title>Fix possible login(1) argument injection in telnetd(8). [SA-16:36]</title>
<updated>2016-12-06T18:50:06Z</updated>
<author>
<name>Gleb Smirnoff</name>
<email>glebius@FreeBSD.org</email>
</author>
<published>2016-12-06T18:50:06Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=eb302dbc19f895b99b9ca7521d05389ee7559d73'/>
<id>urn:sha1:eb302dbc19f895b99b9ca7521d05389ee7559d73</id>
<content type='text'>
Fix link_ntoa(3) buffer overflow in libc. [SA-16:37]
Fix warnings about valid time zone abbreviations. [EN-16:19]
Update timezone database information. [EN-16:20]

Security:	FreeBSD-SA-16:36.telnetd
Security:	FreeBSD-SA-16:37.libc
Errata Notice:	FreeBSD-EN-16:19.tzcode
Errata Notice:	FreeBSD-EN-16:20.tzdata
Approved by:	so
</content>
</entry>
<entry>
<title>o Fix invalid TCP checksums with pf(4). [EN-16:02.pf]</title>
<updated>2016-01-14T09:11:26Z</updated>
<author>
<name>Gleb Smirnoff</name>
<email>glebius@FreeBSD.org</email>
</author>
<published>2016-01-14T09:11:26Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=b6dd8ce45df1801c33c3b5e0603af10d1074e5f6'/>
<id>urn:sha1:b6dd8ce45df1801c33c3b5e0603af10d1074e5f6</id>
<content type='text'>
o Fix YP/NIS client library critical bug. [EN-16:03.yplib]
o Fix SCTP ICMPv6 error message vulnerability. [SA-16:01.sctp]
o Fix ntp panic threshold bypass vulnerability. [SA-16:02.ntp]
o Fix Linux compatibility layer incorrect futex handling. [SA-16:03.linux]
o Fix Linux compatibility layer setgroups(2) system call. [SA-16:04.linux]
o Fix TCP MD5 signature denial of service. [SA-16:05.tcp]
o Fix insecure default bsnmpd.conf permissions. [SA-16:06.bsnmpd]

Errata:		FreeBSD-EN-16:02.pf
Errata:		FreeBSD-EN-16:03.yplib
Security:	FreeBSD-SA-16:01.sctp, CVE-2016-1879
Security:	FreeBSD-SA-16:02.ntp, CVE-2015-5300
Security:	FreeBSD-SA-16:03.linux, CVE-2016-1880
Security:	FreeBSD-SA-16:04.linux, CVE-2016-1881
Security:	FreeBSD-SA-16:05.tcp, CVE-2016-1882
Security:	FreeBSD-SA-16:06.bsnmpd, CVE-2015-5677
Approved by:	so
</content>
</entry>
<entry>
<title>[EN-15:08] Revised: Improvements to sendmail TLS/DH interoperability.</title>
<updated>2015-06-30T23:21:48Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2015-06-30T23:21:48Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=bb2a154066c594a74d136eb0ced1a44b8454b015'/>
<id>urn:sha1:bb2a154066c594a74d136eb0ced1a44b8454b015</id>
<content type='text'>
[EN-15:09] Fix inconsistency between locale and rune locale states.

Approved by:	so
</content>
</entry>
<entry>
<title>MFS r268218 (MFC r267912, r267915):</title>
<updated>2014-07-03T16:26:37Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2014-07-03T16:26:37Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=1b7f455aea8f99fdb0ba69209cbb43f762fa9dd2'/>
<id>urn:sha1:1b7f455aea8f99fdb0ba69209cbb43f762fa9dd2</id>
<content type='text'>
- Exclude loopback address rather than loopback interface.
- style(9)

Spotted by:	melifaro
Approved by:	re (gjb)
</content>
</entry>
<entry>
<title>MFS r268053 (MFC r267800):</title>
<updated>2014-07-01T18:05:38Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2014-07-01T18:05:38Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=58f4b53eca19502751a2cd66bd5da36a8618ef23'/>
<id>urn:sha1:58f4b53eca19502751a2cd66bd5da36a8618ef23</id>
<content type='text'>
Exclude IPv4 address from doing longest match.
It prevented DNS based load balancing.

Approved by:	re (delphij)
</content>
</entry>
<entry>
<title>MFS r267876 (MFC r267616):</title>
<updated>2014-07-01T17:31:47Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2014-07-01T17:31:47Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=c51853ba05d902cb20d5520bad80b38bafe89532'/>
<id>urn:sha1:c51853ba05d902cb20d5520bad80b38bafe89532</id>
<content type='text'>
Retooling addrconfig() to exclude addresses on loopback interfaces
when looking for configured addresses.
This change is based upon the code from the submitter, and made
following changes:
- Exclude addresses assigned on interfaces which are down, like NetBSD
  does.
- Exclude addresses assigned on interfaces which are ifdisabled.

PR:		190824
Submitted by:	Justin McOmie
Approved by:	re (marius)
</content>
</entry>
<entry>
<title>Cumulative update to arc4random(3).</title>
<updated>2014-06-12T00:15:07Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2014-06-12T00:15:07Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=52bd6a0b74bf158671f5c04575088cd14cc56741'/>
<id>urn:sha1:52bd6a0b74bf158671f5c04575088cd14cc56741</id>
<content type='text'>
MFC r227519, r227520, r238118, r241046:

r227519 (das)

Sync the style, comments, and variable names of arc4random.c with
OpenBSD's version (r1.22).  No functional changes, as verified with
md5.

r227520 (das)

Further reduce diffs with OpenBSD's arc4random.  The main functional
change here is to ensure that when a process forks after arc4random
is seeded, the parent and child don't observe the same random sequence.
OpenBSD's fix introduces some additional overhead in the form of a
getpid() call.

The only significant remaining difference between our arc4random and
OpenBSD's is in how we seed the generator in arc4_stir().

r238118 (pjd):

Prefer sysctl to open/read/close for obtaining random data.

This method is more sandbox-friendly and also should be faster as only
one syscall is needed instead of three.
In case of an error fall back to the old method.

r241046 (jilles)

libc: Use O_CLOEXEC for various internal file descriptors.

Approved by:	re (gjb)
</content>
</entry>
<entry>
<title>MFC r260913,266895:</title>
<updated>2014-06-08T21:21:54Z</updated>
<author>
<name>Nathan Whitehorn</name>
<email>nwhitehorn@FreeBSD.org</email>
</author>
<published>2014-06-08T21:21:54Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=a72aa1f44742b69d914a67ebba3d615c23dd8b9c'/>
<id>urn:sha1:a72aa1f44742b69d914a67ebba3d615c23dd8b9c</id>
<content type='text'>
Add a new flag to /etc/ttys: onifconsole. This is equivalent to "on" if the
device is an active kernel console and "off" otherwise. This is designed to
allow serial-booting x86 systems to provide a login prompt on the serial line
by default without providing one on all systems by default. Set this flag
on x86 systems for ttyu0.

Comments and suggestions by:	grehan, dteske, jilles
Approved by:	re (gjb)
Relnotes:	yes
</content>
</entry>
<entry>
<title>MFC r266285,266866:</title>
<updated>2014-06-02T20:23:41Z</updated>
<author>
<name>Benjamin Kaduk</name>
<email>bjk@FreeBSD.org</email>
</author>
<published>2014-06-02T20:23:41Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=98618dc15656a6ba6d6d61e75af4204ef39cad89'/>
<id>urn:sha1:98618dc15656a6ba6d6d61e75af4204ef39cad89</id>
<content type='text'>
    ------------------------------------------------------------------------
    r266285 | bjk | 2014-05-16 23:05:52 -0400 (Fri, 16 May 2014) | 9 lines

    Correct documentation of the limit on how much memory can be mlock()ed

    vm.max_wired is a system-wide limit, not per-process.  Reword the
    section to make this more clear.

    PR:             docs/189214
    Submitted by:   Lawrence Chen (original text)
    Approved by:    hrs (mentor)

    ------------------------------------------------------------------------
    r266866 | bjk | 2014-05-29 22:16:28 -0400 (Thu, 29 May 2014) | 5 lines

    Minor mdoc fix

    Submitted by:   hrs
    Approved by:    hrs (mentor, implicit)

    ------------------------------------------------------------------------

PR:		189214
Approved by:	re (gjb), hrs (mentor)
</content>
</entry>
</feed>
