From owner-svn-src-releng@freebsd.org Mon Sep 19 15:17:40 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 2EA88BE0060; Mon, 19 Sep 2016 15:17:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id D9F611F7; Mon, 19 Sep 2016 15:17:39 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JFHdiW013974; Mon, 19 Sep 2016 15:17:39 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JFHdNb013973; Mon, 19 Sep 2016 15:17:39 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191517.u8JFHdNb013973@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 15:17:39 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305975 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 15:17:40 -0000 Author: gjb Date: Mon Sep 19 15:17:38 2016 New Revision: 305975 URL: https://svnweb.freebsd.org/changeset/base/305975 Log: Remove entry for r304246. Update entry for r299142. Update entry for r260910. Add entry for r296277. Submitted by: jhb, vangyzen Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 15:08:03 2016 (r305974) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 15:17:38 2016 (r305975) @@ -215,9 +215,8 @@ Allow &man.pciconf.8; to identify PCI devices that are attached to a driver to be identified by their device name instead of just the selector. Additionally, - an optional device argument to the -l flag - to restrict the output to only listing details about a single - device. + the -l flag now accepts an optional device + argument to list details about a single device. A new flag, onifconsole has been added to /etc/ttys. This allows @@ -1070,6 +1069,16 @@ KERN_DEBUGDIR="" to &man.src.conf.5;. + Support for POSIX asynchronous I/O is + now included in the kernel by default. The + VFS_AIOkernel option and + aio.ko kernel module have been removed. + Asynchronous I/O operations on sockets, local files, and + disk devices are permitted by default. However, operations + on other file types are disabled. See the &man.aio.4; + manual page for more details. + &arch.arm64; has been switched over to using INTRNG by default. @@ -1356,12 +1365,14 @@ Hardware Support - Native PCI-express HotPlug - support is enabled by default on &arch.amd64;, &arch.arm64; and - &arch.powerpc; - - PCI-express HotPlug support has been - enabled for slots with power controllers + Native PCI-express HotPlug support is + enabled by default on &arch.amd64;, &arch.arm64;, and + &arch.powerpc;. This feature has exposed compatibility issues + on some hardware that result in missing devices or a hang + during boot. To work around such issues, run set + hw.pci.enable_pcie_hp=0 in the boot loader, and + add hw.pci.enable_pcie_hp=0 to + /boot/loader.conf. The &man.asmc.4; driver has been updated to support the &apple; MacMini 3,1. From owner-svn-src-releng@freebsd.org Mon Sep 19 15:39:26 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 11675BE06CC; Mon, 19 Sep 2016 15:39:26 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id CEF811AB; Mon, 19 Sep 2016 15:39:25 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JFdPU8021883; Mon, 19 Sep 2016 15:39:25 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JFdPtG021882; Mon, 19 Sep 2016 15:39:25 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191539.u8JFdPtG021882@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 15:39:25 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305976 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 15:39:26 -0000 Author: gjb Date: Mon Sep 19 15:39:24 2016 New Revision: 305976 URL: https://svnweb.freebsd.org/changeset/base/305976 Log: Whitespace fixes to the 11.0 release notes. No content changes. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 15:17:38 2016 (r305975) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 15:39:24 2016 (r305976) @@ -193,15 +193,16 @@ The MK_ARM_EABI &man.src.conf.5; option has been removed. - The WITH_SYSTEM_COMPILER - &man.src.conf.5; option is enabled by default. + The + WITH_SYSTEM_COMPILER &man.src.conf.5; + option is enabled by default. The ntp suite has been updated to version 4.2.8p8. The - /etc/ntp/leap-seconds - has been updated to version 3676752000. + /etc/ntp/leap-seconds has been updated to + version 3676752000. @@ -468,10 +469,11 @@ system. By default the &man.ifconfig.8; utility - will set the default regulatory domain to FCC - on wireless interfaces. As a result, newly created wireless - interfaces with default settings will have less chances to - violate country-specific regulations. + will set the default regulatory domain to + FCC on wireless interfaces. As a result, + newly created wireless interfaces with default settings will + have less chances to violate country-specific + regulations. @@ -486,8 +488,8 @@ SSHv1 support has been removed from OpenSSH. - Support for DSA is disabled by default in - OpenSSH. + Support for DSA is disabled by default + in OpenSSH. mdocml has been updated to version 1.12.3. @@ -627,39 +629,39 @@ compiler_rt utility has been updated to version 3.8.0. - ACPICA has been - updated to version 20160527. + ACPICA has + been updated to version 20160527. - OpenBSM has been - updated to version 1.2 alpha 4. + OpenBSM has + been updated to version 1.2 alpha 4. libucl has been updated to version 0.8.0. - The NetBSD - Project's &man.libblacklist.3; library and applications + The + NetBSD Project's &man.libblacklist.3; library and applications have been ported and integrated into the system. Packet filtering support for the &man.pf.4; packet filtering systems - has been implemented. The blacklist - system provides the blacklistd - daemon, the helper script - blacklistd-helper to make changes - to the running packet filter system and the + has been implemented. The + blacklist system provides the + blacklistd daemon, the helper + script blacklistd-helper to make + changes to the running packet filter system and the blacklistctl control program. A selection of system daemons, including: fingerd, ftpd, rlogind, and rshd have been modified to support - sending notifications to the blacklistd - daemon. + sending notifications to the + blacklistd daemon. - Support for - the &man.ipfw.4; packet filter has been added to the + Support + for the &man.ipfw.4; packet filter has been added to the blacklistd-helper script. - Support for - the &man.ipfilter.4; packet filter has been added to the + Support + for the &man.ipfilter.4; packet filter has been added to the blacklistd-helper script. @@ -1034,7 +1036,7 @@ configuration by default. A new kernel configuration option, + sponsor="&limelight;">A new kernel configuration option, EM_MULTIQUEUE, has been added which enables multi-queue support in the &man.em.4; driver. @@ -1071,16 +1073,16 @@ Support for POSIX asynchronous I/O is - now included in the kernel by default. The - VFS_AIOkernel option and - aio.ko kernel module have been removed. - Asynchronous I/O operations on sockets, local files, and - disk devices are permitted by default. However, operations - on other file types are disabled. See the &man.aio.4; - manual page for more details. + now included in the kernel by default. The + VFS_AIOkernel option and + aio.ko kernel module have been removed. + Asynchronous I/O operations on sockets, local files, and + disk devices are permitted by default. However, operations + on other file types are disabled. See the &man.aio.4; + manual page for more details. &arch.arm64; has been switched over to using + arch="arm64">&arch.arm64; has been switched over to using INTRNG by default. @@ -1251,9 +1253,9 @@ The &man.ctl.4; driver has been updated to support CD-ROM and removable devices. - The &man.isp.4; driver has - been updated and improved: added support for 16Gbps FC cards, - improved target mode support, completed Multi-ID (NPIV) + The &man.isp.4; driver + has been updated and improved: added support for 16Gbps FC + cards, improved target mode support, completed Multi-ID (NPIV) functionality. @@ -1471,8 +1473,8 @@ updated to support DSM TRIM commands for virtual AHCI disks. - Native graphics support has been added to - the &man.bhyve.8; hypervisor. + Native graphics support has been added + to the &man.bhyve.8; hypervisor. Support for the QEMU virt system @@ -1510,8 +1512,9 @@ to include support for blkif indirect segment I/O. - Indirect segment I/O is enabled by default - in the Xen blkfront driver when running on AWS EC2. + Indirect segment I/O is enabled by + default in the Xen blkfront driver when running on AWS + EC2. @@ -1571,27 +1574,28 @@ &man.ow.temp.4; for more information. Support for the HiSilicon HI6220 SoC has been - added. + sponsor="&abt;">Support for the HiSilicon HI6220 SoC has + been added. The second CPU core on Allwinner A20 SoC have been enabled. - Support for the Allwinner H3 SoC - has been added. + Support for the Allwinner H3 + SoC has been added. - Support for X-Powers AXP813 and - AXP818 power management integrated circuits have been added. + Support for X-Powers AXP813 + and AXP818 power management integrated circuits have been + added. Support for GPIO, Sensors and - interrupts on AXP209 power management integrated circuits have been - added. + interrupts on AXP209 power management integrated circuits have + been added. Support for the Allwinner Reduced Serial Bus (RSB) has been added. - Support for Allwinner A20 HDMI - has been added. + Support for Allwinner A20 + HDMI has been added. @@ -1637,19 +1641,22 @@ GELI-backed SSD storage providers. - - Leading spaces are now stripped off SCSI disk serial - numbers when populating the CAM serial number. This affects the output of - &man.diskinfo.8; and the names of /dev/diskid/DISK-* - device nodes, among other things. - - - Support for managing Shingled Magnetic Recording (SMR) drives - has been added. + Leading spaces are now stripped off + SCSI disk serial numbers when populating + the CAM serial number. This affects the output of + &man.diskinfo.8; and the names of + /dev/diskid/DISK-* device nodes, among + other things. + + Support for managing Shingled + Magnetic Recording (SMR) drives has been added. The - &man.camcontrol.8; command can manually force updating capacity - data after a disk gets resized using the reprobe subcommand. + &man.camcontrol.8; command can manually force updating + capacity data after a disk gets resized using the reprobe + subcommand. @@ -1670,11 +1677,11 @@ noac, and proto options have been added to &man.mount.nfs.8;. - The Mellanox implementation of iSER (iSCSI - Extensions for RDMA) has been imported. + The Mellanox implementation of iSER + (iSCSI Extensions for RDMA) has been imported. - The ability to discover iSCSI targets without - having to attach to a target has been added to the + The ability to discover iSCSI targets + without having to attach to a target has been added to the &man.iscsictl.8; command. @@ -1695,17 +1702,18 @@ account when gathering buffers to be written to the l2arc device. - The zfsd daemon has been added, - which manages hotspares and replements in drive slots that publish - physical paths. - - The - minimum and maximum values for the ZFS adaptive replacement - cache can be modified at runtime. + The zfsd daemon has been added, which manages + hotspares and replements in drive slots that publish physical + paths. + + The minimum and maximum values for the + ZFS adaptive replacement cache can be modified at + runtime. - Four new - resources have been added to &man.rctl.8; to allow + Four + new resources have been added to &man.rctl.8; to allow throttles to be set on filesystem IO. @@ -1771,8 +1779,9 @@ ttyu2, and ttyu3 by default, if the callin port is an active console port. - The default installation directory for modules - has been changed to /boot/modules. + The default installation directory for + modules has been changed to + /boot/modules. @@ -1788,11 +1797,12 @@ This section describes changes that affect networking in &os;. - The unused SIOCSIFALIFETIME_IN6 - ioctl has been removed. + The unused + SIOCSIFALIFETIME_IN6 ioctl has been + removed. - Support to - be able to reroot into a NFSv4 volume has been added. + Support + to be able to reroot into a NFSv4 volume has been added. Network Protocols @@ -1892,8 +1902,9 @@ network stack has been updated to fix handling of IPv6 On-Link redirects. - The net.inet.tcp.ecn.enable sysctl mib has been - changed from a binary off/on control to a three way setting. + The net.inet.tcp.ecn.enable sysctl mib + has been changed from a binary off/on control to a three way + setting. @@ -1905,7 +1916,6 @@ Description - 0 @@ -1914,23 +1924,22 @@ 1 - Enable ECN if incoming connections request it. Outgoing - connections will request ECN. + Enable ECN if incoming connections request it. + Outgoing connections will request ECN. 2 - Enable ECN if incoming connections request it. Outgoing - conections will not request ECN. + Enable ECN if incoming connections request it. + Outgoing conections will not request ECN. - - Dummynet AQM, an independent implementation of - CoDel and FQ-CoDel for ipfw/dummynet has been imported to the base - system. + Dummynet AQM, an independent + implementation of CoDel and FQ-CoDel for ipfw/dummynet has + been imported to the base system. From owner-svn-src-releng@freebsd.org Mon Sep 19 16:05:12 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0D144BE0F07; Mon, 19 Sep 2016 16:05:12 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id DD749662; Mon, 19 Sep 2016 16:05:11 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JG5BX3032980; Mon, 19 Sep 2016 16:05:11 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JG5Bmm032979; Mon, 19 Sep 2016 16:05:11 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191605.u8JG5Bmm032979@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 16:05:11 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305979 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 16:05:12 -0000 Author: gjb Date: Mon Sep 19 16:05:10 2016 New Revision: 305979 URL: https://svnweb.freebsd.org/changeset/base/305979 Log: Sort by SVN revision. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 15:58:45 2016 (r305978) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 16:05:10 2016 (r305979) @@ -193,16 +193,16 @@ The MK_ARM_EABI &man.src.conf.5; option has been removed. - The - WITH_SYSTEM_COMPILER &man.src.conf.5; - option is enabled by default. - The ntp suite has been updated to version 4.2.8p8. The /etc/ntp/leap-seconds has been updated to version 3676752000. + + The + WITH_SYSTEM_COMPILER &man.src.conf.5; + option is enabled by default. @@ -482,15 +482,6 @@ &man.byacc.1; has been updated to version 20140101. - OpenSSH has - been updated to 7.2p2. - - SSHv1 support has been removed from - OpenSSH. - - Support for DSA is disabled by default - in OpenSSH. - mdocml has been updated to version 1.12.3. @@ -532,9 +523,6 @@ elftoolchain utilities have been updated to version 3179. - The &man.xz.1; utility has been updated - to version 5.2.2. - The &man.nvi.1; utility has been updated to version 2.1.3. @@ -542,10 +530,6 @@ &man.hostapd.8; utilities have been updated to version 2.4. - The - &man.resolvconf.8; utility has been updated to version - 3.7.3. - bmake has been updated to version 20150606. @@ -568,9 +552,6 @@ The &man.tcpdump.1; utility has been updated to version 4.7.4. - OpenSSL has - been updated to version 1.0.2h. - The &man.ssh.1; utility has been updated to re-implement hostname canonicalization before locating the host in @@ -591,10 +572,6 @@ The &man.svnlite.1; utility has been updated to version 1.8.14. - The sqlite3 - library used by &man.svnlite.1; and &man.kerberos.8; has been - updated to version 3.12.1. - Timezone data files have been updated to version 2015f. @@ -607,12 +584,15 @@ &man.jemalloc.3; has been updated to version 4.0.2. - The &man.file.1; utility has been - updated to version 5.28. - The &man.nc.1; utility has been updated to the OpenBSD 5.8 version. + The &man.xz.1; utility has been updated + to version 5.2.2. + + OpenBSM has + been updated to version 1.2 alpha 4. + Clang has been updated to version 3.8.0. @@ -629,15 +609,26 @@ compiler_rt utility has been updated to version 3.8.0. - ACPICA has - been updated to version 20160527. + The + &man.resolvconf.8; utility has been updated to version + 3.7.3. - OpenBSM has - been updated to version 1.2 alpha 4. + OpenSSH has + been updated to 7.2p2. + + The sqlite3 + library used by &man.svnlite.1; and &man.kerberos.8; has been + updated to version 3.12.1. libucl has been updated to version 0.8.0. + OpenSSL has + been updated to version 1.0.2h. + + ACPICA has + been updated to version 20160527. + The NetBSD Project's &man.libblacklist.3; library and applications have been ported and integrated into the system. Packet @@ -663,6 +654,15 @@ Support for the &man.ipfilter.4; packet filter has been added to the blacklistd-helper script. + + The &man.file.1; utility has been + updated to version 5.28. + + SSHv1 support has been removed from + OpenSSH. + + Support for DSA is disabled by default + in OpenSSH. @@ -1367,15 +1367,6 @@ Hardware Support - Native PCI-express HotPlug support is - enabled by default on &arch.amd64;, &arch.arm64;, and - &arch.powerpc;. This feature has exposed compatibility issues - on some hardware that result in missing devices or a hang - during boot. To work around such issues, run set - hw.pci.enable_pcie_hp=0 in the boot loader, and - add hw.pci.enable_pcie_hp=0 to - /boot/loader.conf. - The &man.asmc.4; driver has been updated to support the &apple; MacMini 3,1. @@ -1418,6 +1409,15 @@ Initial SMP support has been added to the &os;/&arch.arm64; port. + + Native PCI-express HotPlug support is + enabled by default on &arch.amd64;, &arch.arm64;, and + &arch.powerpc;. This feature has exposed compatibility issues + on some hardware that result in missing devices or a hang + during boot. To work around such issues, run set + hw.pci.enable_pcie_hp=0 in the boot loader, and + add hw.pci.enable_pcie_hp=0 to + /boot/loader.conf. @@ -1473,9 +1473,6 @@ updated to support DSM TRIM commands for virtual AHCI disks. - Native graphics support has been added - to the &man.bhyve.8; hypervisor. - Support for the QEMU virt system has been added. @@ -1515,6 +1512,9 @@ Indirect segment I/O is enabled by default in the Xen blkfront driver when running on AWS EC2. + + Native graphics support has been added + to the &man.bhyve.8; hypervisor. @@ -1587,15 +1587,15 @@ and AXP818 power management integrated circuits have been added. - Support for GPIO, Sensors and - interrupts on AXP209 power management integrated circuits have - been added. - Support for the Allwinner Reduced Serial Bus (RSB) has been added. Support for Allwinner A20 HDMI has been added. + + Support for GPIO, Sensors and + interrupts on AXP209 power management integrated circuits have + been added. @@ -1617,10 +1617,6 @@ &man.ctld.8; utility has been updated to allow controlling non-iSCSI &man.ctl.4; ports. - Support - for parsing libucl-based configuration files has been added to - &man.ctld.8;. - The &man.autofs.5; subsystem has been updated to include a new &man.auto.master.5; map, -media, which @@ -1641,6 +1637,15 @@ GELI-backed SSD storage providers. + Support + for parsing libucl-based configuration files has been added to + &man.ctld.8;. + + The + &man.camcontrol.8; command can manually force updating + capacity data after a disk gets resized using the reprobe + subcommand. + Leading spaces are now stripped off SCSI disk serial numbers when populating @@ -1652,11 +1657,6 @@ Support for managing Shingled Magnetic Recording (SMR) drives has been added. - - The - &man.camcontrol.8; command can manually force updating - capacity data after a disk gets resized using the reprobe - subcommand. @@ -1702,6 +1702,10 @@ account when gathering buffers to be written to the l2arc device. + Four + new resources have been added to &man.rctl.8; to allow + throttles to be set on filesystem IO. + The zfsd daemon has been added, which manages hotspares and replements in drive slots that publish physical @@ -1711,10 +1715,6 @@ sponsor="&multiplay;">The minimum and maximum values for the ZFS adaptive replacement cache can be modified at runtime. - - Four - new resources have been added to &man.rctl.8; to allow - throttles to be set on filesystem IO. @@ -1797,13 +1797,6 @@ This section describes changes that affect networking in &os;. - The unused - SIOCSIFALIFETIME_IN6 ioctl has been - removed. - - Support - to be able to reroot into a NFSv4 volume has been added. - Network Protocols @@ -1902,6 +1895,10 @@ network stack has been updated to fix handling of IPv6 On-Link redirects. + Support + to be able to reroot into a NFSv4 volume has been + added. + The net.inet.tcp.ecn.enable sysctl mib has been changed from a binary off/on control to a three way setting. @@ -1941,6 +1938,9 @@ implementation of CoDel and FQ-CoDel for ipfw/dummynet has been imported to the base system. + The unused + SIOCSIFALIFETIME_IN6 ioctl has been + removed. From owner-svn-src-releng@freebsd.org Mon Sep 19 17:17:30 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id D4B7FBE1280; Mon, 19 Sep 2016 17:17:30 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 95684863; Mon, 19 Sep 2016 17:17:30 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JHHTZ1059898; Mon, 19 Sep 2016 17:17:29 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JHHTOi059897; Mon, 19 Sep 2016 17:17:29 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191717.u8JHHTOi059897@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 17:17:29 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305986 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 17:17:30 -0000 Author: gjb Date: Mon Sep 19 17:17:29 2016 New Revision: 305986 URL: https://svnweb.freebsd.org/changeset/base/305986 Log: - Remove the Security Advisories and Errata Notices section, which are not relevant for a dot-zero release. - Reword the entry for r261498. - Remove a duplicate entry. - Document byacc(1) update to 20160324. - Document mdocml(1) update to 20160116. - Capitalize 'Sendmail'. - Document svnlite(1) update to 1.9.4. - Document tzdata update to 2015g. - Reword the entry for r288090, and update upstream version. - Reword the entry for r301169. - Fix spacing for r296277 entry. - Remove the empty 'Boot Menu', 'Ports', and 'Documentaton' sections. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 17:16:51 2016 (r305985) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Mon Sep 19 17:17:29 2016 (r305986) @@ -150,25 +150,6 @@ - - Security and Errata - - This section lists the various Security Advisories and - Errata Notices since &release.prev;. - - - Security Advisories - - &security; - - - - Errata Notices - - &errata; - - - Userland @@ -228,9 +209,9 @@ Support for displaying VPD for PCI devices via &man.pciconf.8; has been added. - &man.ping.8; protects against malicious - network packets using the Capsicum framework to drop - privileges. + The &man.ping.8; utility has been + updated to use the Capsicum framework to drop priviliges, + protecting against malicious network packets. The &man.ps.1; utility has been updated to include the -J flag, used to @@ -479,12 +460,6 @@ Contributed Software - &man.byacc.1; has been updated to - version 20140101. - - mdocml has - been updated to version 1.12.3. - The binutils suite of utilities has been updated to include upstream patches that add new relocations for &arch.powerpc; @@ -511,11 +486,6 @@ strings were switched to the versions from the ELF Tool Chain project. - The libedit library - has been updated to include UTF-8 support, - adding UTF-8 support to the &man.sh.1; - shell. - The &man.xz.1; utility has been updated to support multi-threaded compression. @@ -533,7 +503,7 @@ bmake has been updated to version 20150606. - sendmail has + Sendmail has been updated to 8.15.2. Starting with &os; 11.0 and sendmail 8.15, sendmail uses uncompressed IPv6 addresses by default, i.e., they will not contain ::. For @@ -569,27 +539,24 @@ library used by &man.svnlite.1; has been updated to version 1.3.8. - The &man.svnlite.1; utility has been - updated to version 1.8.14. - - Timezone data files have been updated to - version 2015f. - The &man.acpi.4; subsystem has been updated to version 20150818. The &man.unbound.8; utility has been updated to version 1.5.4. - &man.jemalloc.3; has been updated to - version 4.0.2. - The &man.nc.1; utility has been updated to the OpenBSD 5.8 version. + Timezone data files have been updated to + version 2015g. + The &man.xz.1; utility has been updated to version 5.2.2. + The &man.mandoc.1; utility has been + updated to version 20160116. + OpenBSM has been updated to version 1.2 alpha 4. @@ -616,6 +583,9 @@ OpenSSH has been updated to 7.2p2. + The &man.byacc.1; utility has been + updated to version 20160324. + The sqlite3 library used by &man.svnlite.1; and &man.kerberos.8; has been updated to version 3.12.1. @@ -623,6 +593,9 @@ libucl has been updated to version 0.8.0. + The &man.svnlite.1; utility has been + updated to version 1.9.4. + OpenSSL has been updated to version 1.0.2h. @@ -630,10 +603,9 @@ been updated to version 20160527. The - NetBSD Project's &man.libblacklist.3; library and applications - have been ported and integrated into the system. Packet - filtering support for the &man.pf.4; packet filtering systems - has been implemented. The + &man.libblacklist.3; library and applications have been ported + from the NetBSD Project. Packet filtering support for the + &man.pf.4; packet filtering systems has been implemented. The blacklist system provides the blacklistd daemon, the helper script blacklistd-helper to make @@ -647,6 +619,9 @@ sending notifications to the blacklistd daemon. + The &man.jemalloc.3; library has been + updated to version 4.2.1. + Support for the &man.ipfw.4; packet filter has been added to the blacklistd-helper script. @@ -1074,7 +1049,7 @@ Support for POSIX asynchronous I/O is now included in the kernel by default. The - VFS_AIOkernel option and + VFS_AIO kernel option and aio.ko kernel module have been removed. Asynchronous I/O operations on sockets, local files, and disk devices are permitted by default. However, operations @@ -1783,12 +1758,6 @@ modules has been changed to /boot/modules. - - - Boot Menu Changes - -   - @@ -1944,45 +1913,6 @@ - - Ports Collection and Package Infrastructure - - This section covers changes to the &os; Ports - Collection, package infrastructure, and package maintenance and - installation tools. - - - Infrastructure Changes - -   - - - - Packaging Changes - -   - - - - - Documentation - - This section covers changes to the &os; Documentation - Project sources and toolchain. - - - Documentation Source Changes - -   - - - - Documentation Toolchain Changes - -   - - - Release Engineering and Integration From owner-svn-src-releng@freebsd.org Mon Sep 19 18:40:55 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 50572BE18D6; Mon, 19 Sep 2016 18:40:55 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 2E5F1138F; Mon, 19 Sep 2016 18:40:55 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JIes08091250; Mon, 19 Sep 2016 18:40:54 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JIesYv091248; Mon, 19 Sep 2016 18:40:54 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191840.u8JIesYv091248@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 18:40:54 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305992 - in releng/11.0/release/doc: en_US.ISO8859-1/readme share/xml X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 18:40:55 -0000 Author: gjb Date: Mon Sep 19 18:40:54 2016 New Revision: 305992 URL: https://svnweb.freebsd.org/changeset/base/305992 Log: - Fix various entities in the release.ent file. - Update the readme.html copyright year. - Fix a malformed URL. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/readme/article.xml releng/11.0/release/doc/share/xml/release.ent Modified: releng/11.0/release/doc/en_US.ISO8859-1/readme/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/readme/article.xml Mon Sep 19 18:36:26 2016 (r305991) +++ releng/11.0/release/doc/en_US.ISO8859-1/readme/article.xml Mon Sep 19 18:40:54 2016 (r305992) @@ -21,22 +21,7 @@ $FreeBSD$ - 2000 - 2001 - 2002 - 2003 - 2004 - 2005 - 2006 - 2007 - 2008 - 2009 - 2010 - 2011 - 2012 - 2013 - 2014 - 2015 + 2016 The &os; Documentation Project @@ -338,8 +323,10 @@ other copies are kept updated on the Internet and should be consulted as the current errata for this release. These other copies of the errata are located at - &url.base;/releases/ (as - well as any sites which keep up-to-date mirrors of this + the &os; &release.current; + page (as well as any sites which keep up-to-date + mirrors of this location). Modified: releng/11.0/release/doc/share/xml/release.ent ============================================================================== --- releng/11.0/release/doc/share/xml/release.ent Mon Sep 19 18:36:26 2016 (r305991) +++ releng/11.0/release/doc/share/xml/release.ent Mon Sep 19 18:40:54 2016 (r305992) @@ -6,7 +6,7 @@ - + - + - + @@ -37,7 +37,7 @@ or "release" --> - + From owner-svn-src-releng@freebsd.org Mon Sep 19 19:18:02 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 7508DBE0627; Mon, 19 Sep 2016 19:18:02 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 50867398; Mon, 19 Sep 2016 19:18:02 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JJI1X3005998; Mon, 19 Sep 2016 19:18:01 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JJI1AV005996; Mon, 19 Sep 2016 19:18:01 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191918.u8JJI1AV005996@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 19:18:01 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305996 - releng/11.0/release/doc/en_US.ISO8859-1/installation X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 19:18:02 -0000 Author: gjb Date: Mon Sep 19 19:18:01 2016 New Revision: 305996 URL: https://svnweb.freebsd.org/changeset/base/305996 Log: Add the installation documentation files. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Added: releng/11.0/release/doc/en_US.ISO8859-1/installation/ releng/11.0/release/doc/en_US.ISO8859-1/installation/Makefile (contents, props changed) releng/11.0/release/doc/en_US.ISO8859-1/installation/article.xml (contents, props changed) Added: releng/11.0/release/doc/en_US.ISO8859-1/installation/Makefile ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ releng/11.0/release/doc/en_US.ISO8859-1/installation/Makefile Mon Sep 19 19:18:01 2016 (r305996) @@ -0,0 +1,19 @@ +# $FreeBSD$ + +RELN_ROOT?= ${.CURDIR}/../.. +.ifdef NO_LANGCODE_IN_DESTDIR +DESTDIR?= ${DOCDIR}/installation +.else +DESTDIR?= ${DOCDIR}/en_US.ISO8859-1/installation +.endif + +DOC?= article +FORMATS?= html +INSTALL_COMPRESSED?= gz +INSTALL_ONLY_COMPRESSED?= + +# SGML content +SRCS+= article.xml + +.include "${RELN_ROOT}/share/mk/doc.relnotes.mk" +.include "${DOC_PREFIX}/share/mk/doc.project.mk" Added: releng/11.0/release/doc/en_US.ISO8859-1/installation/article.xml ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ releng/11.0/release/doc/en_US.ISO8859-1/installation/article.xml Mon Sep 19 19:18:01 2016 (r305996) @@ -0,0 +1,125 @@ + + +%release; + +]> + +
+ &os; &release.current; Installation Instructions + + The &os; Project + + $FreeBSD$ + + + 2016 + The &os; Documentation Project + + + + &tm-attrib.freebsd; + &tm-attrib.intel; + &tm-attrib.sparc; + &tm-attrib.general; + + + + This article gives some brief instructions on installing + &os; &release.current; and upgrading the systems running earlier + releases. + + + + + Installing &os; + + The Installing + &os; + chapter of the &os; + Handbook provides more in-depth information about the + installation program itself, including a guided walk-through with + screenshots. + + + + Upgrading &os; + + If you are upgrading from a previous release of &os;, please + read upgrading + section in the Release Notes for notable + incompatibilities carefully. + + + Upgrading from Source + + The procedure for doing a source code based update is + described in + and + . + + For SVN use the releng/&local.rel; branch + which will be where any upcoming Security Advisories or Errata + Notices will be applied. + + + + Upgrading Using <quote>&os; Update</quote> + + The &man.freebsd-update.8; utility supports binary + upgrades of &arch.i386; and &arch.amd64; systems running + earlier FreeBSD releases. Systems running + 9.3-RELEASE, + 10.1-RELEASE, + 10.2-RELEASE, + 10.3-RELEASE, + 11.0-RC[123] can upgrade as follows: + + &prompt.root; freebsd-update fetch +&prompt.root; freebsd-update install + + Now the &man.freebsd-update.8; utility can fetch bits + belonging to &release.current;. During this process + &man.freebsd-update.8; will ask for help in merging + configuration files. + + &prompt.root; freebsd-update upgrade -r &local.rel;-RELEASE + + &prompt.root; freebsd-update install + + The system must now be rebooted with the newly installed + kernel before the non-kernel components are updated. + + &prompt.root; shutdown -r now + + After rebooting, &man.freebsd-update.8; needs to be run + again to install the new userland components: + + &prompt.root; freebsd-update install + + At this point, users of systems being upgraded from + earlier &os; releases will be prompted by + &man.freebsd-update.8; to rebuild all third-party applications + (e.g., ports installed from the ports tree) due to updates in + system libraries. + + After updating installed third-party applications (and + again, only if &man.freebsd-update.8; printed a message + indicating that this was necessary), run + &man.freebsd-update.8; again so that it can delete the old (no + longer used) system libraries: + + &prompt.root; freebsd-update install + + Finally, reboot into &release.current; + + &prompt.root; shutdown -r now + + +
From owner-svn-src-releng@freebsd.org Mon Sep 19 19:18:41 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id F0579BE06C7; Mon, 19 Sep 2016 19:18:41 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C1A72795; Mon, 19 Sep 2016 19:18:41 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8JJIfdx006060; Mon, 19 Sep 2016 19:18:41 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8JJIevD006059; Mon, 19 Sep 2016 19:18:40 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609191918.u8JJIevD006059@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Mon, 19 Sep 2016 19:18:40 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r305997 - releng/11.0/release/doc/en_US.ISO8859-1 X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Sep 2016 19:18:42 -0000 Author: gjb Date: Mon Sep 19 19:18:40 2016 New Revision: 305997 URL: https://svnweb.freebsd.org/changeset/base/305997 Log: Connect the installation/article.xml to the build. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/Makefile Modified: releng/11.0/release/doc/en_US.ISO8859-1/Makefile ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/Makefile Mon Sep 19 19:18:01 2016 (r305996) +++ releng/11.0/release/doc/en_US.ISO8859-1/Makefile Mon Sep 19 19:18:40 2016 (r305997) @@ -6,6 +6,7 @@ SUBDIR = relnotes SUBDIR+= hardware SUBDIR+= readme SUBDIR+= errata +SUBDIR+= installation COMPAT_SYMLINK = en From owner-svn-src-releng@freebsd.org Tue Sep 20 16:14:43 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 351B7BE19C7; Tue, 20 Sep 2016 16:14:43 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 07D1E18D; Tue, 20 Sep 2016 16:14:42 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGEgak082602; Tue, 20 Sep 2016 16:14:42 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGEgPw082601; Tue, 20 Sep 2016 16:14:42 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201614.u8KGEgPw082601@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:14:42 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306028 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:14:43 -0000 Author: gjb Date: Tue Sep 20 16:14:42 2016 New Revision: 306028 URL: https://svnweb.freebsd.org/changeset/base/306028 Log: Document bsdinstall(8) hardening menu. Submitted by: robak Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 15:14:33 2016 (r306027) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:14:42 2016 (r306028) @@ -685,6 +685,10 @@ sponsor="&scaleengine;">Support for selecting the partitioning scheme when installing on the UFS filesystem has been added to &man.bsdinstall.8;. + + The &man.bsdinstall.8; utility has been + updated to include various system hardening options during + installation. From owner-svn-src-releng@freebsd.org Tue Sep 20 16:31:01 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 12225BE216B; Tue, 20 Sep 2016 16:31:01 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BE273871; Tue, 20 Sep 2016 16:31:00 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGUx7b086923; Tue, 20 Sep 2016 16:30:59 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGUxHk086922; Tue, 20 Sep 2016 16:30:59 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201630.u8KGUxHk086922@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:30:59 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306032 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:31:01 -0000 Author: gjb Date: Tue Sep 20 16:30:59 2016 New Revision: 306032 URL: https://svnweb.freebsd.org/changeset/base/306032 Log: Document r298002, NCQ TRIM support, CAM_IOSCHED_ADATPIVE. Submitted by: imp Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:28:57 2016 (r306031) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:30:59 2016 (r306032) @@ -1620,6 +1620,30 @@ for parsing libucl-based configuration files has been added to &man.ctld.8;. + The &man.ahci.4; driver has been updated + to add NCQ TRIM support + for drives that support it. + + + Drives that advertise this feature but do not properly + support it have been blacklisted. Systems experiencing + traffic problems with NCQ + TRIM enabled can set the + kern.cam.ada.%d.quirks tunable to + 2 for 512k sectors or + 3 for 4096k sectors, replacing + %d with the drive number. + + + The &man.cam.4; driver has been updated to + allow I/O scheduling tuning to fit workload and drive + characteristics. This option is off by default, and can be + enabled by adding option + CAM_IOSCHED_ADATPIVE option to the kernel + configuration and recompiling the kernel. + The &man.camcontrol.8; command can manually force updating capacity data after a disk gets resized using the reprobe From owner-svn-src-releng@freebsd.org Tue Sep 20 16:35:58 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EA38CBE23B6; Tue, 20 Sep 2016 16:35:58 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id B94A6128A; Tue, 20 Sep 2016 16:35:58 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGZvmP090896; Tue, 20 Sep 2016 16:35:57 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGZv68090895; Tue, 20 Sep 2016 16:35:57 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201635.u8KGZv68090895@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:35:57 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306034 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:35:59 -0000 Author: gjb Date: Tue Sep 20 16:35:57 2016 New Revision: 306034 URL: https://svnweb.freebsd.org/changeset/base/306034 Log: Document 285307, cloudabi Submitted by: ed Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:31:57 2016 (r306033) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:35:57 2016 (r306034) @@ -1035,6 +1035,13 @@ &man.numactl.1;, and &man.numa.getaffinity.2;, for usage details. + Support for running CloudABI executables + on amd64 and arm64 has been added. CloudABI is a runtime + environment that uses capability-based security exclusively, + similar to &man.capsicum.4; always being enabled. It allows + designing, implementing and testing strongly sandboxed + applications more easily. + The &man.pms.4; driver has been added to the GENERIC kernel configuration for supported architectures. From owner-svn-src-releng@freebsd.org Tue Sep 20 16:36:56 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B6F03BE241A; Tue, 20 Sep 2016 16:36:56 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 899311481; Tue, 20 Sep 2016 16:36:56 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGatRB090978; Tue, 20 Sep 2016 16:36:55 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGat87090977; Tue, 20 Sep 2016 16:36:55 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201636.u8KGat87090977@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:36:55 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306035 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:36:56 -0000 Author: gjb Date: Tue Sep 20 16:36:55 2016 New Revision: 306035 URL: https://svnweb.freebsd.org/changeset/base/306035 Log: Fix an incorrect revision. Submitted by: avos Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:35:57 2016 (r306034) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:36:55 2016 (r306035) @@ -449,7 +449,7 @@ falling back to the PCI ID database in the &os; base system. - By default the &man.ifconfig.8; utility + By default the &man.ifconfig.8; utility will set the default regulatory domain to FCC on wireless interfaces. As a result, newly created wireless interfaces with default settings will From owner-svn-src-releng@freebsd.org Tue Sep 20 16:39:42 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B33E1BE2519; Tue, 20 Sep 2016 16:39:42 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 85E6117BD; Tue, 20 Sep 2016 16:39:42 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGdfGs091158; Tue, 20 Sep 2016 16:39:41 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGdfQN091157; Tue, 20 Sep 2016 16:39:41 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201639.u8KGdfQN091157@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:39:41 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306037 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:39:42 -0000 Author: gjb Date: Tue Sep 20 16:39:41 2016 New Revision: 306037 URL: https://svnweb.freebsd.org/changeset/base/306037 Log: Fix a typo. Submitted by: vangyzen Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:37:02 2016 (r306036) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:39:41 2016 (r306037) @@ -1648,7 +1648,7 @@ allow I/O scheduling tuning to fit workload and drive characteristics. This option is off by default, and can be enabled by adding option - CAM_IOSCHED_ADATPIVE option to the kernel + CAM_IOSCHED_ADAPTIVE option to the kernel configuration and recompiling the kernel. The From owner-svn-src-releng@freebsd.org Tue Sep 20 16:48:26 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id D7AFBBE2A29; Tue, 20 Sep 2016 16:48:26 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id A7E3F393; Tue, 20 Sep 2016 16:48:26 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGmPTT095477; Tue, 20 Sep 2016 16:48:25 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGmPII095476; Tue, 20 Sep 2016 16:48:25 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201648.u8KGmPII095476@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:48:25 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306039 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:48:26 -0000 Author: gjb Date: Tue Sep 20 16:48:25 2016 New Revision: 306039 URL: https://svnweb.freebsd.org/changeset/base/306039 Log: Update the entry for r279463, and move it to the correct section. Submitted by: rstone Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:40:15 2016 (r306038) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:48:25 2016 (r306039) @@ -711,12 +711,6 @@ equivalent script is available from the net/mrouted port. - A new &man.rc.8; script, - iovctl, has been added, which allows - automatically starting the &man.iovctl.8; utility at - boot. - The &man.service.8; utility has been updated to honor entries within + Support for PCI Single Root I/O + Virtualization (SR-IOV) has been introduced, allowing the + creation of PCI Virtual Functions (VFs) for device drivers + that support SR-IOV. See &man.iovctl.8; for details on + creating and configuring VFs. + The &man.bhyve.8; hypervisor has been updated to support DSM TRIM commands for virtual AHCI disks. From owner-svn-src-releng@freebsd.org Tue Sep 20 16:56:00 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EB02FBE2D15; Tue, 20 Sep 2016 16:56:00 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BD3A4BD5; Tue, 20 Sep 2016 16:56:00 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KGu06Q099216; Tue, 20 Sep 2016 16:56:00 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KGu0NH099215; Tue, 20 Sep 2016 16:56:00 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201656.u8KGu0NH099215@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 16:55:59 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306040 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 16:56:01 -0000 Author: gjb Date: Tue Sep 20 16:55:59 2016 New Revision: 306040 URL: https://svnweb.freebsd.org/changeset/base/306040 Log: Expand the r285387 entry to include information for cases where NUMA may be disabled due to system BIOS. Submitted by: vangyzen Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:48:25 2016 (r306039) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 16:55:59 2016 (r306040) @@ -1029,6 +1029,14 @@ &man.numactl.1;, and &man.numa.getaffinity.2;, for usage details. + + If the system BIOS generates an invalid ACPI SRAT table, + the kernel will ignore it, effectively disabling + NUMA. If dmesg shows "SRAT: + Duplicate local APIC ID", try updating the BIOS to fix + NUMA support. + + Support for running CloudABI executables on amd64 and arm64 has been added. CloudABI is a runtime environment that uses capability-based security exclusively, From owner-svn-src-releng@freebsd.org Tue Sep 20 17:26:03 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 66024BE2C1E; Tue, 20 Sep 2016 17:26:03 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 3611190B; Tue, 20 Sep 2016 17:26:03 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KHQ2cX011252; Tue, 20 Sep 2016 17:26:02 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KHQ2PX011251; Tue, 20 Sep 2016 17:26:02 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201726.u8KHQ2PX011251@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 17:26:02 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306042 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 17:26:03 -0000 Author: gjb Date: Tue Sep 20 17:26:02 2016 New Revision: 306042 URL: https://svnweb.freebsd.org/changeset/base/306042 Log: - Remove redundant wording. - Update MK_ARM_EABI entry to note it is the default. - Reword the entry for r290910. - Fix various wording nits. - Remove redundant '[arch]' tags where they are already specified. - Various rewordings. Submitted by: theraven (first pass from his feedback) Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:07:14 2016 (r306041) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:26:02 2016 (r306042) @@ -163,7 +163,7 @@ includes files in the /etc/newsyslog.conf.d/ and /usr/local/etc/newsyslog.conf.d/ - directories by default for &man.newsyslog.8;. + directories for &man.newsyslog.8;. The &man.mailwrapper.8; utility has been updated to use &man.mailer.conf.5; from the @@ -172,12 +172,13 @@ if unset. The MK_ARM_EABI - &man.src.conf.5; option has been removed. + &man.src.conf.5; option has been removed and is now the only + supported ABI for &os;/&arch.arm;. The ntp suite has been updated to version 4.2.8p8. - The + /etc/ntp/leap-seconds has been updated to version 3676752000. @@ -194,11 +195,12 @@ &man.dmesg.8; is now printed, opposed to the previous output Exec format error.. - Allow &man.pciconf.8; to identify PCI - devices that are attached to a driver to be identified by - their device name instead of just the selector. Additionally, - the -l flag now accepts an optional device - argument to list details about a single device. + The &man.pciconf.8; utility can now + identify PCI devices that are attached to a driver to be + identified by their device name instead of just the selector. + Additionally, the -l flag now accepts an + optional device argument to list details about a single + device. A new flag, onifconsole has been added to /etc/ttys. This allows @@ -304,8 +306,8 @@ MBR EFI partition type. - The &man.ptrace.2; system - call has been updated include support for Altivec registers on + The &man.ptrace.2; system call has been + updated include support for Altivec registers on &os;/&arch.powerpc;. A new device control utility, @@ -317,14 +319,15 @@ The &man.netstat.1; utility has been - updated to link against the &man.libxo.3; shared - library. + updated to use &man.libxo.3; to optionally generate + machine-readable output. A new flag, -c, has been added to the &man.mkimg.1; utility, which allows specifying the capacity of the target disk image. The + UEFI Secure Boot signing utility, &man.uefisign.8; utility has been added. A new utility, &man.sesutil.8;, has been added, which is used - to manage &man.ses.4; devices. + to manage &man.ses.4; (SCSI Environmental + Services) devices. The &man.pciconf.8; utility has been updated to use the PCI ID database from the The &man.xz.1; utility has been updated to support multi-threaded compression. - The - elftoolchain utilities have been - updated to version 3179. - The &man.nvi.1; utility has been updated to version 2.1.3. @@ -869,11 +869,11 @@ &man.sysctl.8; on &intel; processors with Turbo Boost ™ enabled has been fixed. - Support for - &man.dtrace.1; stack tracing has been fixed for - &os;/&arch.powerpc;, using the trapexit() - and asttrapexit() functions instead of - checking within addressed kernel space. + Support for &man.dtrace.1; stack tracing + has been fixed for &os;/&arch.powerpc;, using the + trapexit() and + asttrapexit() functions instead of checking + within addressed kernel space. A kernel panic triggered when destroying a &man.vnet.9; &man.jail.8; configured with &man.gif.4; has @@ -907,9 +907,8 @@ - Support for - &man.dtrace.1; has been added for the - Book-E ™. + Support for &man.dtrace.1; has been + added for the PowerPC Book-E ™. The &man.kqueue.2; system call has been @@ -923,7 +922,7 @@ The IMAGACT_BINMISC kernel configuration option has been enabled by default, which enables application execution through emulators, such - as Qemu. + as QEMU. The VT kernel configuration file has been removed, and the &man.vt.4; @@ -938,10 +937,9 @@ class="directory">src/ tree, specified as an argument to the -s flag. - The - &os;/&arch.powerpc64; kernel now builds as - a position-independent executable, allowing the kernel to be - loaded into and run from any physical or virtual + The &os;/&arch.powerpc64; kernel now + builds as a position-independent executable, allowing the + kernel to be loaded into and run from any physical or virtual address. @@ -950,7 +948,7 @@ system. - A new module for creating + A new module for creating rpi.dtb has been added for the Raspberry Pi. @@ -959,15 +957,13 @@ /boot/dtb/ by default for the Raspberry Pi system. - Kernel support for Vector-Scalar eXtension - (VSX) found on POWER7 and POWER8 hardware - has been added. - - The &man.pmap.9; implementation for 64-bit - &powerpc; processors has been overhaulded to improve - concurrency. + Kernel + support for Vector-Scalar eXtension (VSX) + found on POWER7 and POWER8 hardware has been added. + + The + &man.pmap.9; implementation for 64-bit &powerpc; processors + has been overhaulded to improve concurrency. A new module for creating the dtb module for AM335x systems has @@ -994,7 +990,7 @@ configuration has been added, allowing building &man.siftr.4; statically into the kernel. - The &arch.arm; boot loader, + The &arm; boot loader, ubldr, is now relocatable. In addition, ubldr.bin is now created during build time, which is a stripped binary with an entry point of @@ -1518,32 +1514,31 @@ The &man.nand.4; device is enabled for ARM devices by default. - Support for the Exynos 5420 - Octa system has been added. + Support for the Exynos 5420 Octa system + has been added. - The SMP - option has been enabled for all Exynos 5 systems supported by + The SMP option has + been enabled for all Exynos 5 systems supported by &os;. - Support for the Toradex - Apalis i.MX6 development board has been added. + Support for the Toradex Apalis i.MX6 + development board has been added. - An issue that could cause - instability when detecting SD cards on the - Raspberry Pi SOC has been fixed. + An issue that could cause instability + when detecting SD cards on the Raspberry Pi + SOC has been fixed. The bcm2835_cpufreq driver has been added, which supports CPU frequency and voltage control on the Raspberry Pi SOC. - Support to turn off the - BeagleBone Black system with the &man.shutdown.8; - -p flag or by invoking &man.poweroff.8; has - been added. + Support to turn off the BeagleBone Black + system with the &man.shutdown.8; -p flag or + by invoking &man.poweroff.8; has been added. - Audio transmission drivers - have been added for Digital Audio Multiplexer + Audio transmission drivers have been + added for Digital Audio Multiplexer (AUDMUXM), Smart Direct Memory Access Controller (SDMA), and Syncronous Serial Interface (SSI). @@ -1552,14 +1547,13 @@ support for the ARM AArch64 architecture has been added. - Kernel support for Thumb-2 - userland has been added. + Kernel support for Thumb-2 userland has + been added. - Support for the hardware power button - on the BeagleBone Black system has been added. + Support for the hardware power button on + the BeagleBone Black system has been added. - Initial + Initial ACPI support has been added for &os;/&arch.arm64;. @@ -1568,29 +1562,28 @@ &man.gpio.4;. See &man.ow.4;, &man.owc.4;, and &man.ow.temp.4; for more information. - Support for the HiSilicon HI6220 SoC has - been added. + been added. - The second CPU core on - Allwinner A20 SoC have been enabled. + The second CPU core on Allwinner A20 SoC + have been enabled. - Support for the Allwinner H3 - SoC has been added. + Support for the Allwinner H3 SoC has + been added. - Support for X-Powers AXP813 - and AXP818 power management integrated circuits have been - added. + Support for X-Powers AXP813 and AXP818 + power management integrated circuits have been added. - Support for the Allwinner - Reduced Serial Bus (RSB) has been added. + Support for the Allwinner Reduced Serial + Bus (RSB) has been added. - Support for Allwinner A20 - HDMI has been added. + Support for Allwinner A20 HDMI has been + added. - Support for GPIO, Sensors and - interrupts on AXP209 power management integrated circuits have - been added. + Support for GPIO, Sensors and interrupts + on AXP209 power management integrated circuits have been + added.
From owner-svn-src-releng@freebsd.org Tue Sep 20 17:30:35 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3C860BE2D81; Tue, 20 Sep 2016 17:30:35 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 0F4EDC82; Tue, 20 Sep 2016 17:30:34 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KHUYM5011556; Tue, 20 Sep 2016 17:30:34 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KHUYM4011555; Tue, 20 Sep 2016 17:30:34 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201730.u8KHUYM4011555@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 17:30:34 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306043 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 17:30:35 -0000 Author: gjb Date: Tue Sep 20 17:30:34 2016 New Revision: 306043 URL: https://svnweb.freebsd.org/changeset/base/306043 Log: Document r289315, resolver reloads resolv.conf if mtime changes. Fix a spacing nit while here. Submitted by: vangyzen Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:26:02 2016 (r306042) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:30:34 2016 (r306043) @@ -453,6 +453,11 @@ falling back to the PCI ID database in the &os; base system. + The + resolver library has been updated to reload + /etc/resolv.conf if the modification time + has changed. + By default the &man.ifconfig.8; utility will set the default regulatory domain to FCC on wireless interfaces. As a result, @@ -1564,7 +1569,7 @@ Support for the HiSilicon HI6220 SoC has - been added. + been added. The second CPU core on Allwinner A20 SoC have been enabled. From owner-svn-src-releng@freebsd.org Tue Sep 20 17:53:35 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 089F6BE279A; Tue, 20 Sep 2016 17:53:35 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id CCC80F7C; Tue, 20 Sep 2016 17:53:34 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KHrYXO022597; Tue, 20 Sep 2016 17:53:34 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KHrYPS022596; Tue, 20 Sep 2016 17:53:34 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201753.u8KHrYPS022596@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 17:53:34 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306044 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 17:53:35 -0000 Author: gjb Date: Tue Sep 20 17:53:33 2016 New Revision: 306044 URL: https://svnweb.freebsd.org/changeset/base/306044 Log: Document r300779, dummynet(4) AQM addition. Submitted by: truckman Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:30:34 2016 (r306043) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:53:33 2016 (r306044) @@ -1342,6 +1342,13 @@ The &man.lagg.4; driver has been updated to remove support for the fec protocol. + + The &man.dummynet.4; driver has been + updated to include support for AQM (Active + Queue Management), adding support for PIE + (Proportional Integral controller Enhanced) and + FQ-PIE (Fair Queueing Proportional Integral + controller Enhanced). From owner-svn-src-releng@freebsd.org Tue Sep 20 18:02:18 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 1DEF3BE2A58; Tue, 20 Sep 2016 18:02:18 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C7190766; Tue, 20 Sep 2016 18:02:17 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KI2Gj3026496; Tue, 20 Sep 2016 18:02:16 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KI2G6h026495; Tue, 20 Sep 2016 18:02:16 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201802.u8KI2G6h026495@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 18:02:16 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306045 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 18:02:18 -0000 Author: gjb Date: Tue Sep 20 18:02:16 2016 New Revision: 306045 URL: https://svnweb.freebsd.org/changeset/base/306045 Log: Wording fixes and further clarifications. Submitted by: cperciva Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 17:53:33 2016 (r306044) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 18:02:16 2016 (r306045) @@ -242,9 +242,9 @@ The &man.primes.6; utility has been updated to correctly enumerate prime numbers between 4295098369 and - 3825123056546413050, which prior to this - change, it would be possible for returned values to be - incorrectly identified as prime numbers. + 3825123056546413050. Prior to this change, + it was possible for returned values to be incorrectly + identified as prime numbers. The &man.mkimg.1; utility has been updated to include three options used to print information @@ -709,7 +709,8 @@ A new &man.rc.8; script, growfs, has been added, which will resize the root filesystem on boot if /firstboot - exists. + exists and growfs_enable is enabled in + &man.rc.conf.5;. The mrouted &man.rc.8; script has been removed from the base system. An @@ -1508,9 +1509,9 @@ &man.hv.netvsc.4; driver has been updated to support checksum offloading and TSO. - The &man.xen.4; driver has been updated - to include support for blkif indirect - segment I/O. + The &man.xen.4; blkfront driver has been + updated to include support for blkif + indirect segment I/O. Indirect segment I/O is enabled by default in the Xen blkfront driver when running on AWS From owner-svn-src-releng@freebsd.org Tue Sep 20 18:38:17 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EEDFEBE2821; Tue, 20 Sep 2016 18:38:17 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BEE8625F; Tue, 20 Sep 2016 18:38:17 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KIcGP4039134; Tue, 20 Sep 2016 18:38:16 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KIcG0W039133; Tue, 20 Sep 2016 18:38:16 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201838.u8KIcG0W039133@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 18:38:16 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306047 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 18:38:18 -0000 Author: gjb Date: Tue Sep 20 18:38:16 2016 New Revision: 306047 URL: https://svnweb.freebsd.org/changeset/base/306047 Log: Document r297678, uuencode(1) '-r' option. Document r302558, ul(1) truncation bug fix. Submitted by: gahr Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 18:08:17 2016 (r306046) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 18:38:16 2016 (r306047) @@ -458,12 +458,21 @@ /etc/resolv.conf if the modification time has changed. + The &man.uuencode.1; utility has been + updated to include a new flag, -r, which + when used will generate raw output similar the + &man.uudecode.1; -r flag. + By default the &man.ifconfig.8; utility will set the default regulatory domain to FCC on wireless interfaces. As a result, newly created wireless interfaces with default settings will have less chances to violate country-specific regulations. + + A bug in the &man.ul.1; utility that + caused lines to be truncated at 512 characters has been + fixed. From owner-svn-src-releng@freebsd.org Tue Sep 20 19:11:41 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EC1F1BE23FA; Tue, 20 Sep 2016 19:11:41 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id AF1E1DE1; Tue, 20 Sep 2016 19:11:41 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KJBe5r053442; Tue, 20 Sep 2016 19:11:40 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KJBeSp053441; Tue, 20 Sep 2016 19:11:40 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201911.u8KJBeSp053441@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 19:11:40 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306051 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 19:11:42 -0000 Author: gjb Date: Tue Sep 20 19:11:40 2016 New Revision: 306051 URL: https://svnweb.freebsd.org/changeset/base/306051 Log: Document r291716, camdd(8). Submitted by: ken Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 19:06:58 2016 (r306050) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 19:11:40 2016 (r306051) @@ -1647,6 +1647,24 @@ GELI-backed SSD storage providers. + The &man.camdd.8; utility has been + added, which allows copying data sequentially to and from + SCSI devices, files, block devices and tape + drives. If the source and/or destination is + a SCSI disk, &man.camdd.8; can use the + asynchronous &man.pass.4; interface to queue multiple I/Os for + improved speed. (ATA passthrough support for &man.camdd.8; is + in development.) + + The &man.pass.4; + SCSI/ATA passthrough + driver now has an asynchronous interface. User applications + may queue many requests, get notification of completion via + &man.kqueue.2; and retrieve status later. &man.camdd.8; is an + example application using the interface. + Support for parsing libucl-based configuration files has been added to &man.ctld.8;. From owner-svn-src-releng@freebsd.org Tue Sep 20 19:15:40 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 85174BE268D; Tue, 20 Sep 2016 19:15:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 564E42E9; Tue, 20 Sep 2016 19:15:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KJFdIJ054280; Tue, 20 Sep 2016 19:15:39 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KJFdnW054279; Tue, 20 Sep 2016 19:15:39 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609201915.u8KJFdnW054279@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 19:15:39 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306052 - releng/11.0/release/doc/share/xml X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 19:15:40 -0000 Author: gjb Date: Tue Sep 20 19:15:39 2016 New Revision: 306052 URL: https://svnweb.freebsd.org/changeset/base/306052 Log: Update the manual page path for 11.0-RELEASE. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/share/xml/release.ent Modified: releng/11.0/release/doc/share/xml/release.ent ============================================================================== --- releng/11.0/release/doc/share/xml/release.ent Tue Sep 20 19:11:40 2016 (r306051) +++ releng/11.0/release/doc/share/xml/release.ent Tue Sep 20 19:15:39 2016 (r306052) @@ -58,7 +58,7 @@ - + From owner-svn-src-releng@freebsd.org Tue Sep 20 20:32:36 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EB2CDBE3F9E; Tue, 20 Sep 2016 20:32:36 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C3B1DAE5; Tue, 20 Sep 2016 20:32:36 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KKWZQb084580; Tue, 20 Sep 2016 20:32:35 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KKWZJb084579; Tue, 20 Sep 2016 20:32:35 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609202032.u8KKWZJb084579@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 20:32:35 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306054 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 20:32:37 -0000 Author: gjb Date: Tue Sep 20 20:32:35 2016 New Revision: 306054 URL: https://svnweb.freebsd.org/changeset/base/306054 Log: Tweak wording and add clarifications for several sections. Submitted by: dhw Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 19:21:41 2016 (r306053) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 20:32:35 2016 (r306054) @@ -141,7 +141,7 @@ Source-based upgrades (those based on recompiling the &os; base system from source code) from previous versions are - supported, according to the instructions in + supported, using the instructions in /usr/src/UPDATING. @@ -467,7 +467,7 @@ will set the default regulatory domain to FCC on wireless interfaces. As a result, newly created wireless interfaces with default settings will - have less chances to violate country-specific + have less chance to violate country-specific regulations. A bug in the &man.ul.1; utility that @@ -507,8 +507,8 @@ The &man.xz.1; utility has been updated to support multi-threaded compression. - The &man.nvi.1; utility has been updated - to version 2.1.3. + The &man.nvi.1; utility and related + utilities have been updated to version 2.1.3. The &man.wpa.supplicant.8; and &man.hostapd.8; utilities have been updated to version @@ -527,11 +527,12 @@ IPv6:0:0 versus IPv6:0. This change requires that configuration data (including maps, files, classes, custom ruleset, etc.) must use the same format, so make certain such - configuration data is upgrading. As a very simple check - search for patterns like 'IPv6:[0-9a-fA-F:]*::' and 'IPv6::'. - To return to the old behavior, set the m4 option - confUSE_COMPRESSED_IPV6_ADDRESSES or the cf - option UseCompressedIPv6Addresses. + configuration data is in place before upgrading. As a very + simple check search for patterns like 'IPv6:[0-9a-fA-F:]*::' + and 'IPv6::'. To return to the old behavior, set the m4 + option confUSE_COMPRESSED_IPV6_ADDRESSES or + the cf option + UseCompressedIPv6Addresses. The &man.tcpdump.1; utility has been updated to version 4.7.4. @@ -717,8 +718,9 @@ A new &man.rc.8; script, growfs, has been added, which will resize - the root filesystem on boot if /firstboot - exists and growfs_enable is enabled in + the root filesystem to fill the device on boot if + /firstboot exists and + growfs_enable is enabled in &man.rc.conf.5;. The mrouted @@ -814,13 +816,13 @@ updated to consistently set errno on failure. - The &man.qsort.3; functions have been - updated to be able to handle 32-bit aligned data on 64-bit - platforms, also providing a significant improvement in 32-bit - workloads. + The &man.qsort.3;-related functions have + been updated to be able to handle 32-bit aligned data on + 64-bit platforms, also providing a significant improvement in + 32-bit workloads. Several standard include headers have - been updated to use of gcc + been updated to make use of gcc attributes, such as __result_use_check(), __alloc_size(), and __nonnull(). From owner-svn-src-releng@freebsd.org Tue Sep 20 21:33:59 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 388FEBE3593; Tue, 20 Sep 2016 21:33:59 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 0220913CB; Tue, 20 Sep 2016 21:33:58 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KLXwAZ007396; Tue, 20 Sep 2016 21:33:58 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KLXwSu007395; Tue, 20 Sep 2016 21:33:58 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609202133.u8KLXwSu007395@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 21:33:58 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306055 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 21:33:59 -0000 Author: gjb Date: Tue Sep 20 21:33:57 2016 New Revision: 306055 URL: https://svnweb.freebsd.org/changeset/base/306055 Log: Tweak the nvi(1) entry to be less clumsy-sounding. Submitted by: lidl Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 20:32:35 2016 (r306054) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 21:33:57 2016 (r306055) @@ -507,7 +507,7 @@ The &man.xz.1; utility has been updated to support multi-threaded compression. - The &man.nvi.1; utility and related + The &man.nvi.1; editor and related utilities have been updated to version 2.1.3. The &man.wpa.supplicant.8; and From owner-svn-src-releng@freebsd.org Tue Sep 20 22:05:53 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 406DBBE3FA3; Tue, 20 Sep 2016 22:05:53 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 13309BD9; Tue, 20 Sep 2016 22:05:53 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KM5qiA018577; Tue, 20 Sep 2016 22:05:52 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KM5qlt018576; Tue, 20 Sep 2016 22:05:52 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609202205.u8KM5qlt018576@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 22:05:52 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306057 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 22:05:53 -0000 Author: gjb Date: Tue Sep 20 22:05:52 2016 New Revision: 306057 URL: https://svnweb.freebsd.org/changeset/base/306057 Log: Fix an incorrect svn revision. Link to the binmiscctl(8) manual in the r266531 entry. Submitted by: sbruno Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 21:38:12 2016 (r306056) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 22:05:52 2016 (r306057) @@ -939,7 +939,8 @@ The IMAGACT_BINMISC kernel configuration option has been enabled by default, which enables application execution through emulators, such - as QEMU. + as QEMU via + &man.binmiscctl.8;. The VT kernel configuration file has been removed, and the &man.vt.4; @@ -1329,7 +1330,7 @@ updated to support Solarflare Flareon Ultra 7000-series chipsets. - The &man.em.4; driver has been updated with improved transmission queue hang detection. From owner-svn-src-releng@freebsd.org Tue Sep 20 23:04:40 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 549B6BE30A1; Tue, 20 Sep 2016 23:04:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 2757C1754; Tue, 20 Sep 2016 23:04:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KN4dkQ040947; Tue, 20 Sep 2016 23:04:39 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KN4ddP040946; Tue, 20 Sep 2016 23:04:39 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609202304.u8KN4ddP040946@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 23:04:39 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306058 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 23:04:40 -0000 Author: gjb Date: Tue Sep 20 23:04:39 2016 New Revision: 306058 URL: https://svnweb.freebsd.org/changeset/base/306058 Log: Document physical wireless devices are no longer listed by default in ifconfig(8) output. Submitted by: woodsb02 Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 22:05:52 2016 (r306057) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 23:04:39 2016 (r306058) @@ -442,6 +442,12 @@ The &man.patch.1; utility has been updated to remove the automatic checkout feature. + The &man.ifconfig.8; utility has + been modified to no longer show physical wireless devices by + default. In order to view available wireless devices on the + system, run sysctl net.wlan.devices. + A new utility, &man.sesutil.8;, has been added, which is used to manage &man.ses.4; (SCSI Environmental From owner-svn-src-releng@freebsd.org Tue Sep 20 23:16:37 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 41F64BE32EE; Tue, 20 Sep 2016 23:16:37 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 12D171C1C; Tue, 20 Sep 2016 23:16:37 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8KNGad9044712; Tue, 20 Sep 2016 23:16:36 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8KNGaKp044711; Tue, 20 Sep 2016 23:16:36 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609202316.u8KNGaKp044711@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Tue, 20 Sep 2016 23:16:36 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306059 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Sep 2016 23:16:37 -0000 Author: gjb Date: Tue Sep 20 23:16:36 2016 New Revision: 306059 URL: https://svnweb.freebsd.org/changeset/base/306059 Log: Revise the entry for r287197, ifconfig(8) did not change, the wireless networking stack changed. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 23:04:39 2016 (r306058) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Tue Sep 20 23:16:36 2016 (r306059) @@ -443,7 +443,7 @@ updated to remove the automatic checkout feature. The &man.ifconfig.8; utility has + sponsor="&netflix;, &nginx;">The wireless network stack has been modified to no longer show physical wireless devices by default. In order to view available wireless devices on the system, run sysctl net.wlan.devices. From owner-svn-src-releng@freebsd.org Wed Sep 21 14:11:19 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C682CBE32AF; Wed, 21 Sep 2016 14:11:19 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 9667B10C0; Wed, 21 Sep 2016 14:11:19 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LEBIQQ082233; Wed, 21 Sep 2016 14:11:18 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LEBIml082232; Wed, 21 Sep 2016 14:11:18 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211411.u8LEBIml082232@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 14:11:18 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306101 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 14:11:19 -0000 Author: gjb Date: Wed Sep 21 14:11:18 2016 New Revision: 306101 URL: https://svnweb.freebsd.org/changeset/base/306101 Log: Document r298243, BIOS+UEFI addition to bsdinstall(8). Submitted by: martymac Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 13:03:55 2016 (r306100) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:11:18 2016 (r306101) @@ -707,6 +707,14 @@ scheme when installing on the UFS filesystem has been added to &man.bsdinstall.8;. + The &man.bsdinstall.8; utility now + supports + a "BIOS+UEFI option + during installation, supporting systems with + UEFI or + BIOS/CSM + capability. + The &man.bsdinstall.8; utility has been updated to include various system hardening options during installation. From owner-svn-src-releng@freebsd.org Wed Sep 21 14:19:03 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 125E2BE39AA; Wed, 21 Sep 2016 14:19:03 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id D40DA1E75; Wed, 21 Sep 2016 14:19:02 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LEJ2Jt085350; Wed, 21 Sep 2016 14:19:02 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LEJ226085349; Wed, 21 Sep 2016 14:19:02 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211419.u8LEJ226085349@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 14:19:01 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306103 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 14:19:03 -0000 Author: gjb Date: Wed Sep 21 14:19:01 2016 New Revision: 306103 URL: https://svnweb.freebsd.org/changeset/base/306103 Log: Document r291292, if_enc(4) addition. Submitted by: ae Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:15:15 2016 (r306102) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:19:01 2016 (r306103) @@ -1433,6 +1433,12 @@ arch="arm64">Initial SMP support has been added to the &os;/&arch.arm64; port. + The + &man.enc.4; driver has been added, providing an interface + through which IPSEC can be used via + &man.kldload.8; without requiring additional kernel and/or + userland changes. + Native PCI-express HotPlug support is enabled by default on &arch.amd64;, &arch.arm64;, and &arch.powerpc;. This feature has exposed compatibility issues From owner-svn-src-releng@freebsd.org Wed Sep 21 14:56:08 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3EA59BE43E8; Wed, 21 Sep 2016 14:56:08 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 114BC66C; Wed, 21 Sep 2016 14:56:08 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LEu7M1099905; Wed, 21 Sep 2016 14:56:07 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LEu72s099904; Wed, 21 Sep 2016 14:56:07 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211456.u8LEu72s099904@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 14:56:07 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306105 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 14:56:08 -0000 Author: gjb Date: Wed Sep 21 14:56:07 2016 New Revision: 306105 URL: https://svnweb.freebsd.org/changeset/base/306105 Log: Document r296177, dtsec(4) driver addition. Document r298237, SMP booting for Book-E platforms was fixed. Document r297001, Book-E can address up to 36-bits of physical RAM. Document r297977, Book-E now supports e500mc and e5500. Submitted by: jhibbits Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:42:23 2016 (r306104) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:56:07 2016 (r306105) @@ -1439,6 +1439,22 @@ &man.kldload.8; without requiring additional kernel and/or userland changes. + The dtsec(4) driver + for Freescale QorIQ SoCs has been added, supporting P2041, + P3041, P5010, and P5020 systems. + + Freescale PowerQUICC and QorIQ systems + now support larger address spaces, equivalent to PAE mode on + &arch.i386;. + + The e500mc and e5500 PowerPC cores are + now supported, supporting most QorIQ systems. + + SMP for Multicore + Freescale QorIQ systems now works correctly for SoCs with the + AP cores in boot holdoff mode (not in + spinloop wait mode). + Native PCI-express HotPlug support is enabled by default on &arch.amd64;, &arch.arm64;, and &arch.powerpc;. This feature has exposed compatibility issues From owner-svn-src-releng@freebsd.org Wed Sep 21 14:59:44 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EE038BE449A; Wed, 21 Sep 2016 14:59:44 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BE62193C; Wed, 21 Sep 2016 14:59:44 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LExhT0000301; Wed, 21 Sep 2016 14:59:43 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LExh7d000300; Wed, 21 Sep 2016 14:59:43 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211459.u8LExh7d000300@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 14:59:43 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306106 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 14:59:45 -0000 Author: gjb Date: Wed Sep 21 14:59:43 2016 New Revision: 306106 URL: https://svnweb.freebsd.org/changeset/base/306106 Log: Document r301033 was sponsored by the FreeBSD Foundation. Submitted by: trasz Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:56:07 2016 (r306105) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:59:43 2016 (r306106) @@ -1771,9 +1771,10 @@ The Mellanox implementation of iSER (iSCSI Extensions for RDMA) has been imported. - The ability to discover iSCSI targets - without having to attach to a target has been added to the - &man.iscsictl.8; command. + The + ability to discover iSCSI targets without having to attach to + a target has been added to the &man.iscsictl.8; + command. From owner-svn-src-releng@freebsd.org Wed Sep 21 15:26:40 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 24DE3BE4A14; Wed, 21 Sep 2016 15:26:40 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id CD5D41A54; Wed, 21 Sep 2016 15:26:39 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LFQdFR012003; Wed, 21 Sep 2016 15:26:39 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LFQd4H012002; Wed, 21 Sep 2016 15:26:39 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211526.u8LFQd4H012002@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 15:26:39 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306107 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 15:26:40 -0000 Author: gjb Date: Wed Sep 21 15:26:38 2016 New Revision: 306107 URL: https://svnweb.freebsd.org/changeset/base/306107 Log: - Remove various '[arch]' references where it is redundant. - Further clarifications to the CUBIEBOARD2 kernel rename, iwn(4) addition, explicitly noting ia64 is Itanium(tm), various other fixes. Submitted by: theraven Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 14:59:43 2016 (r306106) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 15:26:38 2016 (r306107) @@ -997,8 +997,8 @@ &man.pmap.9; implementation for 64-bit &powerpc; processors has been overhaulded to improve concurrency. - A new module for creating - the dtb module for AM335x systems has + A new module for creating the + dtb module for ARM AM335x systems has been added. The @@ -1022,7 +1022,7 @@ configuration has been added, allowing building &man.siftr.4; statically into the kernel. - The &arm; boot loader, + The ARM boot loader, ubldr, is now relocatable. In addition, ubldr.bin is now created during build time, which is a stripped binary with an entry point of @@ -1076,9 +1076,11 @@ to the GENERIC kernel configuration for supported architectures. - The - CUBIEBOARD2 kernel configuration has been - renamed to A20. + The CUBIEBOARD2 + kernel configuration has been renamed to + A20 to add support for other boards with + the A20 processor, such as the Banana + Pi. Kernel debugging symbols are now installed to - Support for the Freescale + Support for the Freescale PCI Root Complex device has been - added. + added to &os;/&arch.powerpc;. The &man.cyapa.4; driver has been added, supporting the Cypress APA I2C trackpad. @@ -1282,13 +1284,6 @@ BCM57767, BCM57782, BCM57786 and BCM57787 has been added to &man.bge.4;. - Support for the &intel; Centrino™ - Wireless-N 135 chipset has been added. - - Firmware for &intel; Centrino™ - Wireless-N 105 devices has been added to the base - system. - The deprecated nve(4) driver has been removed. Users of NVIDIA nForce MCP network adapters are advised to use the &man.nfe.4; driver instead, which has been @@ -1310,8 +1305,9 @@ sponsor="&netgate;">The &man.ath.hal.4; driver has been updated to support the Atheros AR1111 chipset. - Support for the &intel; Centrino™ - Wireless-N 105 chipset has been added. + The &man.iwn.4; driver was added, + providing support for the &intel; Centrino™ Wireless-N + 105 and 135 chipsets. Support for the &man.cxgbe.4; Terminator @@ -1393,8 +1389,8 @@ The &man.asmc.4; driver has been updated to support the &apple; MacMini 3,1. - Support for &os;/ia64 has been dropped - as of &os; 11. + Support for &os;/ia64 (Itanium) has been + dropped as of &os; 11. An issue that could cause a system to hang when entering ACPI @@ -1402,14 +1398,14 @@ RAM) has been corrected in the &man.acpi.4; and &man.pci.4; drivers. - The power management unit + The power management unit subsystem has been updated to support power button events on - certain &arch.powerpc; hardware, such as aluminum + certain PowerPC hardware, such as aluminum PowerBook ®. - The &man.hwpmc.4; - driver has been updated to correct performance counter - sampling on G4 (MPC74xxx) and G5 class processors. + The &man.hwpmc.4; driver has been + updated to correct performance counter sampling on PowerPC G4 + (MPC74xxx) and G5 class processors. The From owner-svn-src-releng@freebsd.org Wed Sep 21 15:29:36 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 7EDD4BE4AAA; Wed, 21 Sep 2016 15:29:36 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4DFF61C1E; Wed, 21 Sep 2016 15:29:36 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LFTZFV012185; Wed, 21 Sep 2016 15:29:35 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LFTZap012184; Wed, 21 Sep 2016 15:29:35 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211529.u8LFTZap012184@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 15:29:35 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306108 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 15:29:36 -0000 Author: gjb Date: Wed Sep 21 15:29:35 2016 New Revision: 306108 URL: https://svnweb.freebsd.org/changeset/base/306108 Log: Correct the entry for r291292, if_enc(4) was updated to be loaded via kldload(8) during runtime, not newly added. Submitted by: Harry Schmalzbauer Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 15:26:38 2016 (r306107) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 15:29:35 2016 (r306108) @@ -1430,10 +1430,9 @@ added to the &os;/&arch.arm64; port. The - &man.enc.4; driver has been added, providing an interface - through which IPSEC can be used via - &man.kldload.8; without requiring additional kernel and/or - userland changes. + &man.enc.4; driver has updated to allow creating an interface + via &man.kldload.8; during runtime without requiring + additional kernel and/or userland changes. The dtsec(4) driver for Freescale QorIQ SoCs has been added, supporting P2041, From owner-svn-src-releng@freebsd.org Wed Sep 21 18:07:07 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E9CEABE4420; Wed, 21 Sep 2016 18:07:07 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id B7C02B02; Wed, 21 Sep 2016 18:07:07 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LI76pg077409; Wed, 21 Sep 2016 18:07:06 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LI76HA077408; Wed, 21 Sep 2016 18:07:06 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211807.u8LI76HA077408@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 18:07:06 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306128 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 18:07:08 -0000 Author: gjb Date: Wed Sep 21 18:07:06 2016 New Revision: 306128 URL: https://svnweb.freebsd.org/changeset/base/306128 Log: Fix ELF Tool Chain revision for releng/11.0. Replace elfcopy with objcopy/strip. Submitted by: emaste Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 17:51:27 2016 (r306127) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 18:07:06 2016 (r306128) @@ -489,9 +489,9 @@ patches that add new relocations for &arch.powerpc; support. - The + The ELF Tool Chain has been updated to - upstream revision r3272. + upstream revision r3477. The texinfo utility and info pages were removed from @@ -503,10 +503,11 @@ The ELF object manipulation tools addr2line, - elfcopy (strip), + objcopy, nm, readelf, - size, and + size, + strip, and strings were switched to the versions from the ELF Tool Chain project. From owner-svn-src-releng@freebsd.org Wed Sep 21 18:12:39 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 6B248BE4AA5; Wed, 21 Sep 2016 18:12:39 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 3B658289; Wed, 21 Sep 2016 18:12:39 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LICciE081035; Wed, 21 Sep 2016 18:12:38 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LICcWU081034; Wed, 21 Sep 2016 18:12:38 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609211812.u8LICcWU081034@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Wed, 21 Sep 2016 18:12:38 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306130 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 18:12:39 -0000 Author: gjb Date: Wed Sep 21 18:12:38 2016 New Revision: 306130 URL: https://svnweb.freebsd.org/changeset/base/306130 Log: Add c++filt, missed in the previous commit. Submitted by: emaste Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 18:07:25 2016 (r306129) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Wed Sep 21 18:12:38 2016 (r306130) @@ -503,6 +503,7 @@ The ELF object manipulation tools addr2line, + c++filt, objcopy, nm, readelf, From owner-svn-src-releng@freebsd.org Wed Sep 21 21:23:10 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E373FBE3540; Wed, 21 Sep 2016 21:23:10 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id B3A8632F; Wed, 21 Sep 2016 21:23:10 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LLN9C8053589; Wed, 21 Sep 2016 21:23:09 GMT (envelope-from bdrewery@FreeBSD.org) Received: (from bdrewery@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LLN9ST053588; Wed, 21 Sep 2016 21:23:09 GMT (envelope-from bdrewery@FreeBSD.org) Message-Id: <201609212123.u8LLN9ST053588@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: bdrewery set sender to bdrewery@FreeBSD.org using -f From: Bryan Drewery Date: Wed, 21 Sep 2016 21:23:09 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306143 - releng/11.0/share/mk X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 21:23:11 -0000 Author: bdrewery Date: Wed Sep 21 21:23:09 2016 New Revision: 306143 URL: https://svnweb.freebsd.org/changeset/base/306143 Log: Disable SYSTEM_COMPILER by default. This is a direct commit to releng/11.0. Having it enabled can lead to a situation where building on one system and installing on another will fail due to not finding cc in the OBJDIR. An actual fix will be made on head separately. PR: 212877 Relnotes: yes Sponsored by: Dell EMC Isilon Approved by: re (gjb) Modified: releng/11.0/share/mk/src.opts.mk Modified: releng/11.0/share/mk/src.opts.mk ============================================================================== --- releng/11.0/share/mk/src.opts.mk Wed Sep 21 20:56:10 2016 (r306142) +++ releng/11.0/share/mk/src.opts.mk Wed Sep 21 21:23:09 2016 (r306143) @@ -158,7 +158,6 @@ __DEFAULT_YES_OPTIONS = \ SOURCELESS_UCODE \ SVNLITE \ SYSCONS \ - SYSTEM_COMPILER \ TALK \ TCP_WRAPPERS \ TCSH \ @@ -190,6 +189,7 @@ __DEFAULT_NO_OPTIONS = \ SHARED_TOOLCHAIN \ SORT_THREADS \ SVN \ + SYSTEM_COMPILER # From owner-svn-src-releng@freebsd.org Wed Sep 21 21:30:47 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 83BF0BE3D65; Wed, 21 Sep 2016 21:30:47 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 3687EAE3; Wed, 21 Sep 2016 21:30:47 +0000 (UTC) (envelope-from bdrewery@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8LLUkx9054011; Wed, 21 Sep 2016 21:30:46 GMT (envelope-from bdrewery@FreeBSD.org) Received: (from bdrewery@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8LLUkNO054010; Wed, 21 Sep 2016 21:30:46 GMT (envelope-from bdrewery@FreeBSD.org) Message-Id: <201609212130.u8LLUkNO054010@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: bdrewery set sender to bdrewery@FreeBSD.org using -f From: Bryan Drewery Date: Wed, 21 Sep 2016 21:30:46 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306144 - releng/11.0/share/man/man5 X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Sep 2016 21:30:47 -0000 Author: bdrewery Date: Wed Sep 21 21:30:46 2016 New Revision: 306144 URL: https://svnweb.freebsd.org/changeset/base/306144 Log: Regenerate. Approved by: re (gjb, implicit) Modified: releng/11.0/share/man/man5/src.conf.5 Modified: releng/11.0/share/man/man5/src.conf.5 ============================================================================== --- releng/11.0/share/man/man5/src.conf.5 Wed Sep 21 21:23:09 2016 (r306143) +++ releng/11.0/share/man/man5/src.conf.5 Wed Sep 21 21:30:46 2016 (r306144) @@ -1,7 +1,7 @@ .\" DO NOT EDIT-- this file is automatically generated. -.\" from FreeBSD: head/tools/build/options/makeman 292283 2015-12-15 18:42:30Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/makeman 292283 2015-12-15 18:42:30Z bdrewery .\" $FreeBSD$ -.Dd June 28, 2016 +.Dd September 21, 2016 .Dt SRC.CONF 5 .Os .Sh NAME @@ -94,56 +94,56 @@ The following list provides a name and s that can be used for source builds. .Bl -tag -width indent .It Va WITHOUT_ACCT -.\" from FreeBSD: head/tools/build/options/WITHOUT_ACCT 223201 2011-06-17 20:47:44Z ed +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ACCT 223201 2011-06-17 20:47:44Z ed Set to not build process accounting tools such as .Xr accton 8 and .Xr sa 8 . .It Va WITHOUT_ACPI -.\" from FreeBSD: head/tools/build/options/WITHOUT_ACPI 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ACPI 156932 2006-03-21 07:50:50Z ru Set to not build .Xr acpiconf 8 , .Xr acpidump 8 and related programs. .It Va WITHOUT_AMD -.\" from FreeBSD: head/tools/build/options/WITHOUT_AMD 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_AMD 183242 2008-09-21 22:02:26Z sam Set to not build .Xr amd 8 , and related programs. .It Va WITHOUT_APM -.\" from FreeBSD: head/tools/build/options/WITHOUT_APM 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_APM 183242 2008-09-21 22:02:26Z sam Set to not build .Xr apm 8 , .Xr apmd 8 and related programs. .It Va WITHOUT_ASSERT_DEBUG -.\" from FreeBSD: head/tools/build/options/WITHOUT_ASSERT_DEBUG 162215 2006-09-11 13:55:27Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ASSERT_DEBUG 162215 2006-09-11 13:55:27Z ru Set to compile programs and libraries without the .Xr assert 3 checks. .It Va WITHOUT_AT -.\" from FreeBSD: head/tools/build/options/WITHOUT_AT 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_AT 183242 2008-09-21 22:02:26Z sam Set to not build .Xr at 1 and related utilities. .It Va WITHOUT_ATM -.\" from FreeBSD: head/tools/build/options/WITHOUT_ATM 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ATM 156932 2006-03-21 07:50:50Z ru Set to not build programs and libraries related to ATM networking. .It Va WITHOUT_AUDIT -.\" from FreeBSD: head/tools/build/options/WITHOUT_AUDIT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_AUDIT 156932 2006-03-21 07:50:50Z ru Set to not build audit support into system programs. .It Va WITHOUT_AUTHPF -.\" from FreeBSD: head/tools/build/options/WITHOUT_AUTHPF 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_AUTHPF 156932 2006-03-21 07:50:50Z ru Set to not build .Xr authpf 8 . .It Va WITHOUT_AUTOFS -.\" from FreeBSD: head/tools/build/options/WITHOUT_AUTOFS 296264 2016-03-01 11:36:10Z trasz +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_AUTOFS 296264 2016-03-01 11:36:10Z trasz Set to not build .Xr autofs 5 related programs, libraries, and kernel modules. .It Va WITH_AUTO_OBJ -.\" from FreeBSD: head/tools/build/options/WITH_AUTO_OBJ 284708 2015-06-22 20:21:57Z sjg +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_AUTO_OBJ 284708 2015-06-22 20:21:57Z sjg Enable automatic creation of objdirs. .Pp This must be set in the environment, make command line, or @@ -151,14 +151,14 @@ This must be set in the environment, mak not .Pa /etc/src.conf . .It Va WITHOUT_BHYVE -.\" from FreeBSD: head/tools/build/options/WITHOUT_BHYVE 277727 2015-01-26 06:44:48Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BHYVE 277727 2015-01-26 06:44:48Z ngie Set to not build or install .Xr bhyve 8 , associated utilities, and examples. .Pp This option only affects amd64/amd64. .It Va WITHOUT_BINUTILS -.\" from FreeBSD: head/tools/build/options/WITHOUT_BINUTILS 286332 2015-08-05 18:30:00Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BINUTILS 286332 2015-08-05 18:30:00Z emaste Set to not build or install binutils (as, ld, objcopy, and objdump ) as part of the normal system build. The resulting system cannot build programs from source. @@ -166,14 +166,14 @@ The resulting system cannot build progra It is a default setting on arm64/aarch64. .It Va WITH_BINUTILS -.\" from FreeBSD: head/tools/build/options/WITH_BINUTILS 295491 2016-02-11 00:14:00Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_BINUTILS 295491 2016-02-11 00:14:00Z emaste Set to build and install binutils (as, ld, objcopy, and objdump) as part of the normal system build. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, i386/i386, mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, pc98/i386, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_BINUTILS_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITHOUT_BINUTILS_BOOTSTRAP 295490 2016-02-10 23:57:09Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BINUTILS_BOOTSTRAP 295490 2016-02-10 23:57:09Z emaste Set to not build binutils (as, ld, objcopy and objdump) as part of the bootstrap process. .Bf -symbolic @@ -184,14 +184,14 @@ toolchain is provided. It is a default setting on arm64/aarch64. .It Va WITH_BINUTILS_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITH_BINUTILS_BOOTSTRAP 295491 2016-02-11 00:14:00Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_BINUTILS_BOOTSTRAP 295491 2016-02-11 00:14:00Z emaste Set build binutils (as, ld, objcopy and objdump) as part of the bootstrap process. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, i386/i386, mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, pc98/i386, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_BLACKLIST -.\" from FreeBSD: head/tools/build/options/WITHOUT_BLACKLIST 301554 2016-06-07 16:35:55Z lidl +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BLACKLIST 301554 2016-06-07 16:35:55Z lidl Set this if you do not want to build blacklistd / blacklistctl. When set, it also enforces the following options: .Pp @@ -200,7 +200,7 @@ When set, it also enforces the following .Va WITHOUT_BLACKLIST_SUPPORT .El .It Va WITHOUT_BLACKLIST_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_BLACKLIST_SUPPORT 301554 2016-06-07 16:35:55Z lidl +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BLACKLIST_SUPPORT 301554 2016-06-07 16:35:55Z lidl Set to build some programs without blacklistd support, like .Xr fingerd 8 , .Xr ftpd 8 , @@ -209,39 +209,39 @@ Set to build some programs without black and .Xr sshd 8 . .It Va WITHOUT_BLUETOOTH -.\" from FreeBSD: head/tools/build/options/WITHOUT_BLUETOOTH 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BLUETOOTH 156932 2006-03-21 07:50:50Z ru Set to not build Bluetooth related kernel modules, programs and libraries. .It Va WITHOUT_BOOT -.\" from FreeBSD: head/tools/build/options/WITHOUT_BOOT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BOOT 156932 2006-03-21 07:50:50Z ru Set to not build the boot blocks and loader. .It Va WITHOUT_BOOTPARAMD -.\" from FreeBSD: head/tools/build/options/WITHOUT_BOOTPARAMD 278192 2015-02-04 10:19:32Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BOOTPARAMD 278192 2015-02-04 10:19:32Z ngie Set to not build or install .Xr bootparamd 8 . .It Va WITHOUT_BOOTPD -.\" from FreeBSD: head/tools/build/options/WITHOUT_BOOTPD 278192 2015-02-04 10:19:32Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BOOTPD 278192 2015-02-04 10:19:32Z ngie Set to not build or install .Xr bootpd 8 . .It Va WITHOUT_BSDINSTALL -.\" from FreeBSD: head/tools/build/options/WITHOUT_BSDINSTALL 277677 2015-01-25 04:43:13Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BSDINSTALL 277677 2015-01-25 04:43:13Z ngie Set to not build .Xr bsdinstall 8 , .Xr sade 8 , and related programs. .It Va WITHOUT_BSD_CPIO -.\" from FreeBSD: head/tools/build/options/WITHOUT_BSD_CPIO 179813 2008-06-16 05:48:15Z dougb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BSD_CPIO 179813 2008-06-16 05:48:15Z dougb Set to not build the BSD licensed version of cpio based on .Xr libarchive 3 . .It Va WITH_BSD_GREP -.\" from FreeBSD: head/tools/build/options/WITH_BSD_GREP 222273 2011-05-25 01:04:12Z obrien +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_BSD_GREP 222273 2011-05-25 01:04:12Z obrien Install BSD-licensed grep as '[ef]grep' instead of GNU grep. .It Va WITHOUT_BSNMP -.\" from FreeBSD: head/tools/build/options/WITHOUT_BSNMP 183306 2008-09-23 16:15:42Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BSNMP 183306 2008-09-23 16:15:42Z sam Set to not build or install .Xr bsnmpd 1 and related libraries and data files. .It Va WITHOUT_BZIP2 -.\" from FreeBSD: head/tools/build/options/WITHOUT_BZIP2 174550 2007-12-12 16:43:17Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BZIP2 174550 2007-12-12 16:43:17Z ru Set to not build contributed bzip2 software as a part of the base system. .Bf -symbolic The option has no effect yet. @@ -253,20 +253,20 @@ When set, it also enforces the following .Va WITHOUT_BZIP2_SUPPORT .El .It Va WITHOUT_BZIP2_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_BZIP2_SUPPORT 166255 2007-01-26 10:19:08Z delphij +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_BZIP2_SUPPORT 166255 2007-01-26 10:19:08Z delphij Set to build some programs without optional bzip2 support. .It Va WITHOUT_CALENDAR -.\" from FreeBSD: head/tools/build/options/WITHOUT_CALENDAR 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CALENDAR 156932 2006-03-21 07:50:50Z ru Set to not build .Xr calendar 1 . .It Va WITHOUT_CAPSICUM -.\" from FreeBSD: head/tools/build/options/WITHOUT_CAPSICUM 229319 2012-01-02 21:57:58Z rwatson +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CAPSICUM 229319 2012-01-02 21:57:58Z rwatson Set to not build Capsicum support into system programs. .It Va WITHOUT_CASPER -.\" from FreeBSD: head/tools/build/options/WITHOUT_CASPER 258838 2013-12-02 08:21:28Z pjd +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CASPER 258838 2013-12-02 08:21:28Z pjd Set to not build Casper program and related libraries. .It Va WITH_CCACHE_BUILD -.\" from FreeBSD: head/tools/build/options/WITH_CCACHE_BUILD 297436 2016-03-30 23:53:12Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CCACHE_BUILD 297436 2016-03-30 23:53:12Z bdrewery Set to use .Xr ccache 1 for the build. @@ -306,12 +306,12 @@ See .Xr ccache 1 for more configuration options. .It Va WITHOUT_CCD -.\" from FreeBSD: head/tools/build/options/WITHOUT_CCD 277678 2015-01-25 04:52:48Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CCD 277678 2015-01-25 04:52:48Z ngie Set to not build .Xr geom_ccd 4 and related utilities. .It Va WITHOUT_CDDL -.\" from FreeBSD: head/tools/build/options/WITHOUT_CDDL 163861 2006-11-01 09:02:11Z jb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CDDL 163861 2006-11-01 09:02:11Z jb Set to not build code licensed under Sun's CDDL. When set, it also enforces the following options: .Pp @@ -322,7 +322,7 @@ When set, it also enforces the following .Va WITHOUT_ZFS .El .It Va WITHOUT_CLANG -.\" from FreeBSD: head/tools/build/options/WITHOUT_CLANG 264660 2014-04-18 17:03:58Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CLANG 264660 2014-04-18 17:03:58Z imp Set to not build the Clang C/C++ compiler during the regular phase of the build. .Pp It is a default setting on @@ -336,13 +336,13 @@ When set, it also enforces the following .Va WITHOUT_CLANG_FULL .El .It Va WITH_CLANG -.\" from FreeBSD: head/tools/build/options/WITH_CLANG 264660 2014-04-18 17:03:58Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CLANG 264660 2014-04-18 17:03:58Z imp Set to build the Clang C/C++ compiler during the normal phase of the build. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386, pc98/i386, powerpc/powerpc and powerpc/powerpc64. .It Va WITHOUT_CLANG_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITHOUT_CLANG_BOOTSTRAP 273177 2014-10-16 18:28:11Z skreuzer +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CLANG_BOOTSTRAP 273177 2014-10-16 18:28:11Z skreuzer Set to not build the Clang C/C++ compiler during the bootstrap phase of the build. You must enable either gcc or clang bootstrap to be able to build the system, unless an alternative compiler is provided via @@ -351,30 +351,30 @@ XCC. It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITH_CLANG_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITH_CLANG_BOOTSTRAP 264660 2014-04-18 17:03:58Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CLANG_BOOTSTRAP 264660 2014-04-18 17:03:58Z imp Set to build the Clang C/C++ compiler during the bootstrap phase of the build. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386 and pc98/i386. .It Va WITH_CLANG_EXTRAS -.\" from FreeBSD: head/tools/build/options/WITH_CLANG_EXTRAS 231057 2012-02-05 23:56:22Z dim +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CLANG_EXTRAS 231057 2012-02-05 23:56:22Z dim Set to build additional clang and llvm tools, such as bugpoint. .It Va WITHOUT_CLANG_FULL -.\" from FreeBSD: head/tools/build/options/WITHOUT_CLANG_FULL 246259 2013-02-02 22:28:29Z dim +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CLANG_FULL 246259 2013-02-02 22:28:29Z dim Set to avoid building the ARCMigrate, Rewriter and StaticAnalyzer components of the Clang C/C++ compiler. .Pp It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32 and sparc64/sparc64. .It Va WITH_CLANG_FULL -.\" from FreeBSD: head/tools/build/options/WITH_CLANG_FULL 246259 2013-02-02 22:28:29Z dim +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CLANG_FULL 246259 2013-02-02 22:28:29Z dim Set to build the ARCMigrate, Rewriter and StaticAnalyzer components of the Clang C/C++ compiler. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386, pc98/i386, powerpc/powerpc and powerpc/powerpc64. .It Va WITHOUT_CLANG_IS_CC -.\" from FreeBSD: head/tools/build/options/WITHOUT_CLANG_IS_CC 242629 2012-11-05 21:53:23Z brooks +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CLANG_IS_CC 242629 2012-11-05 21:53:23Z brooks Set to install the GCC compiler as .Pa /usr/bin/cc , .Pa /usr/bin/c++ @@ -384,7 +384,7 @@ and It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITH_CLANG_IS_CC -.\" from FreeBSD: head/tools/build/options/WITH_CLANG_IS_CC 235342 2012-05-12 16:12:36Z gjb +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CLANG_IS_CC 235342 2012-05-12 16:12:36Z gjb Set to install the Clang C/C++ compiler as .Pa /usr/bin/cc , .Pa /usr/bin/c++ @@ -394,11 +394,11 @@ and It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386 and pc98/i386. .It Va WITHOUT_CPP -.\" from FreeBSD: head/tools/build/options/WITHOUT_CPP 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CPP 156932 2006-03-21 07:50:50Z ru Set to not build .Xr cpp 1 . .It Va WITHOUT_CROSS_COMPILER -.\" from FreeBSD: head/tools/build/options/WITHOUT_CROSS_COMPILER 275138 2014-11-26 20:43:09Z gjb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CROSS_COMPILER 275138 2014-11-26 20:43:09Z gjb Set to not build any cross compiler in the cross-tools stage of buildworld. If you are compiling a different version of .Fx @@ -424,7 +424,7 @@ When set, it also enforces the following .Va WITHOUT_GCC_BOOTSTRAP .El .It Va WITHOUT_CRYPT -.\" from FreeBSD: head/tools/build/options/WITHOUT_CRYPT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CRYPT 156932 2006-03-21 07:50:50Z ru Set to not build any crypto code. When set, it also enforces the following options: .Pp @@ -448,20 +448,20 @@ When set, the following options are also is set explicitly) .El .It Va WITH_CTF -.\" from FreeBSD: head/tools/build/options/WITH_CTF 228159 2011-11-30 18:22:44Z fjoe +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_CTF 228159 2011-11-30 18:22:44Z fjoe Set to compile with CTF (Compact C Type Format) data. CTF data encapsulates a reduced form of debugging information similar to DWARF and the venerable stabs and is required for DTrace. .It Va WITHOUT_CTM -.\" from FreeBSD: head/tools/build/options/WITHOUT_CTM 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CTM 183242 2008-09-21 22:02:26Z sam Set to not build .Xr ctm 1 and related utilities. .It Va WITHOUT_CUSE -.\" from FreeBSD: head/tools/build/options/WITHOUT_CUSE 270171 2014-08-19 15:40:26Z hselasky +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CUSE 270171 2014-08-19 15:40:26Z hselasky Set to not build CUSE-related programs and libraries. .It Va WITHOUT_CXX -.\" from FreeBSD: head/tools/build/options/WITHOUT_CXX 281053 2015-04-03 23:55:04Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_CXX 281053 2015-04-03 23:55:04Z bdrewery Set to not build .Xr c++ 1 and related libraries. @@ -484,14 +484,14 @@ When set, it also enforces the following .Va WITHOUT_GROFF .El .It Va WITHOUT_DEBUG_FILES -.\" from FreeBSD: head/tools/build/options/WITHOUT_DEBUG_FILES 290059 2015-10-27 20:49:56Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_DEBUG_FILES 290059 2015-10-27 20:49:56Z emaste Set to avoid building or installing standalone debug files for each executable binary and shared library. .It Va WITHOUT_DICT -.\" from FreeBSD: head/tools/build/options/WITHOUT_DICT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_DICT 156932 2006-03-21 07:50:50Z ru Set to not build the Webster dictionary files. .It Va WITH_DIRDEPS_BUILD -.\" from FreeBSD: head/tools/build/options/WITH_DIRDEPS_BUILD 298007 2016-04-14 22:00:49Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_DIRDEPS_BUILD 298007 2016-04-14 22:00:49Z bdrewery This is an experimental build system. For details see http://www.crufty.net/sjg/docs/freebsd-meta-mode.htm. @@ -536,10 +536,6 @@ When set, it also enforces the following When set, the following options are also in effect: .Pp .Bl -inset -compact -.It Va WITHOUT_SYSTEM_COMPILER -(unless -.Va WITH_SYSTEM_COMPILER -is set explicitly) .It Va WITH_AUTO_OBJ (unless .Va WITHOUT_AUTO_OBJ @@ -571,7 +567,7 @@ This must be set in the environment, mak not .Pa /etc/src.conf . .It Va WITH_DIRDEPS_CACHE -.\" from FreeBSD: head/tools/build/options/WITH_DIRDEPS_CACHE 290816 2015-11-14 03:24:48Z sjg +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_DIRDEPS_CACHE 290816 2015-11-14 03:24:48Z sjg Cache result of dirdeps.mk which can save significant time for subsequent builds. Depends on @@ -582,47 +578,47 @@ This must be set in the environment, mak not .Pa /etc/src.conf . .It Va WITHOUT_DMAGENT -.\" from FreeBSD: head/tools/build/options/WITHOUT_DMAGENT 262335 2014-02-22 13:05:23Z bapt +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_DMAGENT 262335 2014-02-22 13:05:23Z bapt Set to not build dma Mail Transport Agent .It Va WITHOUT_DOCCOMPRESS -.\" from FreeBSD: head/tools/build/options/WITHOUT_DOCCOMPRESS 266752 2014-05-27 15:52:27Z gjb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_DOCCOMPRESS 266752 2014-05-27 15:52:27Z gjb Set to not to install compressed system documentation. Only the uncompressed version will be installed. .It Va WITH_DTRACE_TESTS -.\" from FreeBSD: head/tools/build/options/WITH_DTRACE_TESTS 286174 2015-08-02 00:37:33Z markj +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_DTRACE_TESTS 286174 2015-08-02 00:37:33Z markj Set to build and install the DTrace test suite in .Pa /usr/tests/cddl/usr.sbin/dtrace . This test suite is considered experimental on architectures other than amd64/amd64 and running it may cause system instability. .It Va WITHOUT_DYNAMICROOT -.\" from FreeBSD: head/tools/build/options/WITHOUT_DYNAMICROOT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_DYNAMICROOT 156932 2006-03-21 07:50:50Z ru Set this if you do not want to link .Pa /bin and .Pa /sbin dynamically. .It Va WITHOUT_ED_CRYPTO -.\" from FreeBSD: head/tools/build/options/WITHOUT_ED_CRYPTO 235660 2012-05-19 20:05:27Z marcel +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ED_CRYPTO 235660 2012-05-19 20:05:27Z marcel Set to build .Xr ed 1 without support for encryption/decryption. .It Va WITHOUT_EE -.\" from FreeBSD: head/tools/build/options/WITHOUT_EE 277663 2015-01-25 00:03:44Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_EE 277663 2015-01-25 00:03:44Z ngie Set to not build and install .Xr edit 1 , .Xr ee 1 , and related programs. .It Va WITH_EISA -.\" from FreeBSD: head/tools/build/options/WITH_EISA 264654 2014-04-18 16:53:06Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_EISA 264654 2014-04-18 16:53:06Z imp Set to build EISA kernel modules. .It Va WITHOUT_ELFCOPY_AS_OBJCOPY -.\" from FreeBSD: head/tools/build/options/WITHOUT_ELFCOPY_AS_OBJCOPY 296193 2016-02-29 16:39:38Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ELFCOPY_AS_OBJCOPY 296193 2016-02-29 16:39:38Z emaste Set to build and install .Xr objcopy 1 from GNU Binutils, instead of the one from ELF Tool Chain. This option is provided as a transition aid and will be removed in due time. .It Va WITHOUT_ELFTOOLCHAIN_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITHOUT_ELFTOOLCHAIN_BOOTSTRAP 295491 2016-02-11 00:14:00Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ELFTOOLCHAIN_BOOTSTRAP 295491 2016-02-11 00:14:00Z emaste Set to not build ELF Tool Chain tools (addr2line, nm, size, strings and strip) as part of the bootstrap process. @@ -630,76 +626,76 @@ as part of the bootstrap process. An alternate bootstrap tool chain must be provided. .Ef .It Va WITHOUT_EXAMPLES -.\" from FreeBSD: head/tools/build/options/WITHOUT_EXAMPLES 156938 2006-03-21 09:06:24Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_EXAMPLES 156938 2006-03-21 09:06:24Z ru Set to avoid installing examples to .Pa /usr/share/examples/ . .It Va WITH_EXTRA_TCP_STACKS -.\" from FreeBSD: head/tools/build/options/WITH_EXTRA_TCP_STACKS 302247 2016-06-28 13:37:01Z jtl +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_EXTRA_TCP_STACKS 302247 2016-06-28 13:37:01Z jtl Set to build extra TCP stack modules. .It Va WITHOUT_FDT -.\" from FreeBSD: head/tools/build/options/WITHOUT_FDT 221539 2011-05-06 19:10:27Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FDT 221539 2011-05-06 19:10:27Z ru Set to not build Flattened Device Tree support as part of the base system. This includes the device tree compiler (dtc) and libfdt support library. .It Va WITHOUT_FILE -.\" from FreeBSD: head/tools/build/options/WITHOUT_FILE 278193 2015-02-04 10:24:40Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FILE 278193 2015-02-04 10:24:40Z ngie Set to not build .Xr file 1 and related programs. .It Va WITHOUT_FINGER -.\" from FreeBSD: head/tools/build/options/WITHOUT_FINGER 278192 2015-02-04 10:19:32Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FINGER 278192 2015-02-04 10:19:32Z ngie Set to not build or install .Xr finger 1 and .Xr fingerd 8 . .It Va WITHOUT_FLOPPY -.\" from FreeBSD: head/tools/build/options/WITHOUT_FLOPPY 221540 2011-05-06 19:13:03Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FLOPPY 221540 2011-05-06 19:13:03Z ru Set to not build or install programs for operating floppy disk driver. .It Va WITHOUT_FMTREE -.\" from FreeBSD: head/tools/build/options/WITHOUT_FMTREE 261299 2014-01-30 21:37:43Z brooks +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FMTREE 261299 2014-01-30 21:37:43Z brooks Set to not build and install .Pa /usr/sbin/fmtree . .It Va WITHOUT_FORMAT_EXTENSIONS -.\" from FreeBSD: head/tools/build/options/WITHOUT_FORMAT_EXTENSIONS 250658 2013-05-15 13:04:10Z brooks +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FORMAT_EXTENSIONS 250658 2013-05-15 13:04:10Z brooks Set to not enable .Fl fformat-extensions when compiling the kernel. Also disables all format checking. .It Va WITHOUT_FORTH -.\" from FreeBSD: head/tools/build/options/WITHOUT_FORTH 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FORTH 156932 2006-03-21 07:50:50Z ru Set to build bootloaders without Forth support. .It Va WITHOUT_FP_LIBC -.\" from FreeBSD: head/tools/build/options/WITHOUT_FP_LIBC 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FP_LIBC 156932 2006-03-21 07:50:50Z ru Set to build .Nm libc without floating-point support. .It Va WITHOUT_FREEBSD_UPDATE -.\" from FreeBSD: head/tools/build/options/WITHOUT_FREEBSD_UPDATE 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FREEBSD_UPDATE 183242 2008-09-21 22:02:26Z sam Set to not build .Xr freebsd-update 8 . .It Va WITHOUT_FTP -.\" from FreeBSD: head/tools/build/options/WITHOUT_FTP 278192 2015-02-04 10:19:32Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_FTP 278192 2015-02-04 10:19:32Z ngie Set to not build or install .Xr ftp 1 and .Xr ftpd 8 . .It Va WITHOUT_GAMES -.\" from FreeBSD: head/tools/build/options/WITHOUT_GAMES 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GAMES 156932 2006-03-21 07:50:50Z ru Set to not build games. .It Va WITHOUT_GCC -.\" from FreeBSD: head/tools/build/options/WITHOUT_GCC 264660 2014-04-18 17:03:58Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GCC 264660 2014-04-18 17:03:58Z imp Set to not build and install gcc and g++ as part of the normal build process. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386 and pc98/i386. .It Va WITH_GCC -.\" from FreeBSD: head/tools/build/options/WITH_GCC 255326 2013-09-06 20:49:48Z zeising +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_GCC 255326 2013-09-06 20:49:48Z zeising Set to build and install gcc and g++. .Pp It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_GCC_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITHOUT_GCC_BOOTSTRAP 273177 2014-10-16 18:28:11Z skreuzer +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GCC_BOOTSTRAP 273177 2014-10-16 18:28:11Z skreuzer Set to not build gcc and g++ as part of the bootstrap process. You must enable either gcc or clang bootstrap to be able to build the system, unless an alternative compiler is provided via @@ -708,32 +704,32 @@ XCC. It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386 and pc98/i386. .It Va WITH_GCC_BOOTSTRAP -.\" from FreeBSD: head/tools/build/options/WITH_GCC_BOOTSTRAP 264660 2014-04-18 17:03:58Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_GCC_BOOTSTRAP 264660 2014-04-18 17:03:58Z imp Set to build gcc and g++ as part of the bootstrap process. .Pp It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_GCOV -.\" from FreeBSD: head/tools/build/options/WITHOUT_GCOV 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GCOV 156932 2006-03-21 07:50:50Z ru Set to not build the .Xr gcov 1 tool. .It Va WITHOUT_GDB -.\" from FreeBSD: head/tools/build/options/WITHOUT_GDB 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GDB 156932 2006-03-21 07:50:50Z ru Set to not build .Xr gdb 1 . .Pp It is a default setting on arm64/aarch64. .It Va WITH_GDB -.\" from FreeBSD: head/tools/build/options/WITH_GDB 295493 2016-02-11 00:30:51Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_GDB 295493 2016-02-11 00:30:51Z emaste Set to build .Xr gdb 1 . .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, i386/i386, mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, pc98/i386, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_GNU -.\" from FreeBSD: head/tools/build/options/WITHOUT_GNU 174550 2007-12-12 16:43:17Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GNU 174550 2007-12-12 16:43:17Z ru Set to not build contributed GNU software as a part of the base system. This option can be useful if the system built must not contain any code covered by the GNU Public License due to legal reasons. @@ -747,37 +743,37 @@ When set, it also enforces the following .Va WITHOUT_GNU_SUPPORT .El .It Va WITHOUT_GNUCXX -.\" from FreeBSD: head/tools/build/options/WITHOUT_GNUCXX 255321 2013-09-06 20:08:03Z theraven +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GNUCXX 255321 2013-09-06 20:08:03Z theraven Do not build the GNU C++ stack (g++, libstdc++). This is the default on platforms where clang is the system compiler. .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, arm64/aarch64, i386/i386 and pc98/i386. .It Va WITH_GNUCXX -.\" from FreeBSD: head/tools/build/options/WITH_GNUCXX 255321 2013-09-06 20:08:03Z theraven +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_GNUCXX 255321 2013-09-06 20:08:03Z theraven Build the GNU C++ stack (g++, libstdc++). This is the default on platforms where gcc is the system compiler. .Pp It is a default setting on mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITHOUT_GNU_GREP_COMPAT -.\" from FreeBSD: head/tools/build/options/WITHOUT_GNU_GREP_COMPAT 273421 2014-10-21 20:44:33Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GNU_GREP_COMPAT 273421 2014-10-21 20:44:33Z emaste Set this option to omit the gnu extensions to grep from being included in BSD grep. .It Va WITHOUT_GNU_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_GNU_SUPPORT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GNU_SUPPORT 156932 2006-03-21 07:50:50Z ru Set to build some programs without optional GNU support. .It Va WITHOUT_GPIO -.\" from FreeBSD: head/tools/build/options/WITHOUT_GPIO 228081 2011-11-28 17:54:34Z dim +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GPIO 228081 2011-11-28 17:54:34Z dim Set to not build .Xr gpioctl 8 as part of the base system. .It Va WITHOUT_GPL_DTC -.\" from FreeBSD: head/tools/build/options/WITHOUT_GPL_DTC 264515 2014-04-15 20:41:55Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GPL_DTC 264515 2014-04-15 20:41:55Z imp Set to build the BSD licensed version of the device tree compiler, instead of the GPL'd one from elinux.org. .It Va WITHOUT_GROFF -.\" from FreeBSD: head/tools/build/options/WITHOUT_GROFF 218941 2011-02-22 08:13:49Z uqs +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GROFF 218941 2011-02-22 08:13:49Z uqs Set to not build .Xr groff 1 and @@ -785,27 +781,27 @@ and You should consider installing the textproc/groff port to not break .Xr man 1 . .It Va WITHOUT_GSSAPI -.\" from FreeBSD: head/tools/build/options/WITHOUT_GSSAPI 174548 2007-12-12 16:39:32Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_GSSAPI 174548 2007-12-12 16:39:32Z ru Set to not build libgssapi. .It Va WITHOUT_HAST -.\" from FreeBSD: head/tools/build/options/WITHOUT_HAST 277725 2015-01-26 06:27:07Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_HAST 277725 2015-01-26 06:27:07Z ngie Set to not build .Xr hastd 8 and related utilities. .It Va WITH_HESIOD -.\" from FreeBSD: head/tools/build/options/WITH_HESIOD 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_HESIOD 156932 2006-03-21 07:50:50Z ru Set to build Hesiod support. .It Va WITHOUT_HTML -.\" from FreeBSD: head/tools/build/options/WITHOUT_HTML 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_HTML 156932 2006-03-21 07:50:50Z ru Set to not build HTML docs. .It Va WITHOUT_HYPERV -.\" from FreeBSD: head/tools/build/options/WITHOUT_HYPERV 271493 2014-09-13 02:15:31Z delphij +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_HYPERV 271493 2014-09-13 02:15:31Z delphij Set to not build or install HyperV utilities. .It Va WITHOUT_ICONV -.\" from FreeBSD: head/tools/build/options/WITHOUT_ICONV 254919 2013-08-26 17:15:56Z antoine +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ICONV 254919 2013-08-26 17:15:56Z antoine Set to not build iconv as part of libc. .It Va WITHOUT_INCLUDES -.\" from FreeBSD: head/tools/build/options/WITHOUT_INCLUDES 275138 2014-11-26 20:43:09Z gjb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INCLUDES 275138 2014-11-26 20:43:09Z gjb Set to not install header files. This option used to be spelled .Va NO_INCS . @@ -813,7 +809,7 @@ This option used to be spelled The option does not work for build targets. .Ef .It Va WITHOUT_INET -.\" from FreeBSD: head/tools/build/options/WITHOUT_INET 221266 2011-04-30 17:58:28Z bz +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INET 221266 2011-04-30 17:58:28Z bz Set to not build programs and libraries related to IPv4 networking. When set, it also enforces the following options: .Pp @@ -822,7 +818,7 @@ When set, it also enforces the following .Va WITHOUT_INET_SUPPORT .El .It Va WITHOUT_INET6 -.\" from FreeBSD: head/tools/build/options/WITHOUT_INET6 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INET6 156932 2006-03-21 07:50:50Z ru Set to not build programs and libraries related to IPv6 networking. When set, it also enforces the following options: @@ -832,17 +828,17 @@ When set, it also enforces the following .Va WITHOUT_INET6_SUPPORT .El .It Va WITHOUT_INET6_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_INET6_SUPPORT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INET6_SUPPORT 156932 2006-03-21 07:50:50Z ru Set to build libraries, programs, and kernel modules without IPv6 support. .It Va WITHOUT_INETD -.\" from FreeBSD: head/tools/build/options/WITHOUT_INETD 278192 2015-02-04 10:19:32Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INETD 278192 2015-02-04 10:19:32Z ngie Set to not build .Xr inetd 8 . .It Va WITHOUT_INET_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_INET_SUPPORT 221266 2011-04-30 17:58:28Z bz +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INET_SUPPORT 221266 2011-04-30 17:58:28Z bz Set to build libraries, programs, and kernel modules without IPv4 support. .It Va WITHOUT_INSTALLLIB -.\" from FreeBSD: head/tools/build/options/WITHOUT_INSTALLLIB 297941 2016-04-13 21:01:58Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_INSTALLLIB 297941 2016-04-13 21:01:58Z bdrewery Set this if you do not want to install optional libraries. For example when creating a .Xr nanobsd 8 @@ -851,7 +847,7 @@ image. The option does not work for build targets. .Ef .It Va WITH_INSTALL_AS_USER -.\" from FreeBSD: head/tools/build/options/WITH_INSTALL_AS_USER 238021 2012-07-02 20:24:01Z marcel +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_INSTALL_AS_USER 238021 2012-07-02 20:24:01Z marcel Set to make install targets succeed for non-root users by installing files with owner and group attributes set to that of the user running the @@ -861,28 +857,28 @@ The user still has to set the .Va DESTDIR variable to point to a directory where the user has write permissions. .It Va WITHOUT_IPFILTER -.\" from FreeBSD: head/tools/build/options/WITHOUT_IPFILTER 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_IPFILTER 156932 2006-03-21 07:50:50Z ru Set to not build IP Filter package. .It Va WITHOUT_IPFW -.\" from FreeBSD: head/tools/build/options/WITHOUT_IPFW 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_IPFW 183242 2008-09-21 22:02:26Z sam Set to not build IPFW tools. .It Va WITHOUT_ISCSI -.\" from FreeBSD: head/tools/build/options/WITHOUT_ISCSI 277675 2015-01-25 04:20:11Z ngie +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_ISCSI 277675 2015-01-25 04:20:11Z ngie Set to not build .Xr iscid 8 and related utilities. .It Va WITHOUT_JAIL -.\" from FreeBSD: head/tools/build/options/WITHOUT_JAIL 249966 2013-04-27 04:09:09Z eadler +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_JAIL 249966 2013-04-27 04:09:09Z eadler Set to not build tools for the support of jails; e.g., .Xr jail 8 . .It Va WITHOUT_KDUMP -.\" from FreeBSD: head/tools/build/options/WITHOUT_KDUMP 240690 2012-09-19 11:38:37Z zeising +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KDUMP 240690 2012-09-19 11:38:37Z zeising Set to not build .Xr kdump 1 and .Xr truss 1 . .It Va WITHOUT_KERBEROS -.\" from FreeBSD: head/tools/build/options/WITHOUT_KERBEROS 174549 2007-12-12 16:42:03Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KERBEROS 174549 2007-12-12 16:42:03Z ru Set this if you do not want to build Kerberos 5 (KTH Heimdal). When set, it also enforces the following options: .Pp @@ -900,7 +896,7 @@ When set, the following options are also is set explicitly) .El .It Va WITHOUT_KERBEROS_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_KERBEROS_SUPPORT 251794 2013-06-15 20:29:07Z eadler +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KERBEROS_SUPPORT 251794 2013-06-15 20:29:07Z eadler Set to build some programs without Kerberos support, like .Xr ssh 1 , .Xr telnet 1 , @@ -908,13 +904,13 @@ Set to build some programs without Kerbe and .Xr telnetd 8 . .It Va WITHOUT_KERNEL_SYMBOLS -.\" from FreeBSD: head/tools/build/options/WITHOUT_KERNEL_SYMBOLS 222189 2011-05-22 18:23:17Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KERNEL_SYMBOLS 222189 2011-05-22 18:23:17Z imp Set to not install kernel symbol files. .Bf -symbolic This option is recommended for those people who have small root partitions. .Ef .It Va WITHOUT_KVM -.\" from FreeBSD: head/tools/build/options/WITHOUT_KVM 174550 2007-12-12 16:43:17Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KVM 174550 2007-12-12 16:43:17Z ru Set to not build the .Nm libkvm library as a part of the base system. @@ -928,12 +924,12 @@ When set, it also enforces the following .Va WITHOUT_KVM_SUPPORT .El .It Va WITHOUT_KVM_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_KVM_SUPPORT 170644 2007-06-13 02:08:04Z sepotvin +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_KVM_SUPPORT 170644 2007-06-13 02:08:04Z sepotvin Set to build some programs without optional .Nm libkvm support. .It Va WITHOUT_LDNS -.\" from FreeBSD: head/tools/build/options/WITHOUT_LDNS 255591 2013-09-15 13:11:13Z des +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LDNS 255591 2013-09-15 13:11:13Z des Setting this variable will prevent the LDNS library from being built. When set, it also enforces the following options: .Pp @@ -944,27 +940,27 @@ When set, it also enforces the following .Va WITHOUT_UNBOUND .El .It Va WITHOUT_LDNS_UTILS -.\" from FreeBSD: head/tools/build/options/WITHOUT_LDNS_UTILS 255850 2013-09-24 14:33:31Z des +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LDNS_UTILS 255850 2013-09-24 14:33:31Z des Setting this variable will prevent building the LDNS utilities .Xr drill 1 and .Xr host 1 . .It Va WITHOUT_LEGACY_CONSOLE -.\" from FreeBSD: head/tools/build/options/WITHOUT_LEGACY_CONSOLE 296264 2016-03-01 11:36:10Z trasz +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LEGACY_CONSOLE 296264 2016-03-01 11:36:10Z trasz Set to not build programs that support a legacy PC console; e.g., .Xr kbdcontrol 1 and .Xr vidcontrol 1 . .It Va WITHOUT_LIB32 -.\" from FreeBSD: head/tools/build/options/WITHOUT_LIB32 274664 2014-11-18 17:06:48Z imp +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LIB32 274664 2014-11-18 17:06:48Z imp On 64-bit platforms, set to not build 32-bit library set and a .Nm ld-elf32.so.1 runtime linker. .It Va WITHOUT_LIBCPLUSPLUS -.\" from FreeBSD: head/tools/build/options/WITHOUT_LIBCPLUSPLUS 246262 2013-02-02 22:42:46Z dim +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LIBCPLUSPLUS 246262 2013-02-02 22:42:46Z dim Set to avoid building libcxxrt and libc++. .It Va WITHOUT_LIBPTHREAD -.\" from FreeBSD: head/tools/build/options/WITHOUT_LIBPTHREAD 188848 2009-02-20 11:09:55Z mtm +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LIBPTHREAD 188848 2009-02-20 11:09:55Z mtm Set to not build the .Nm libpthread providing library, @@ -976,63 +972,63 @@ When set, it also enforces the following .Va WITHOUT_LIBTHR .El .It Va WITH_LIBSOFT -.\" from FreeBSD: head/tools/build/options/WITH_LIBSOFT 300325 2016-05-20 19:23:07Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_LIBSOFT 300325 2016-05-20 19:23:07Z bdrewery On armv6 only, set to enable soft float ABI compatibility libraries. This option is for transitioning to the new hard float ABI. .It Va WITHOUT_LIBTHR -.\" from FreeBSD: head/tools/build/options/WITHOUT_LIBTHR 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LIBTHR 156932 2006-03-21 07:50:50Z ru Set to not build the .Nm libthr (1:1 threading) library. .It Va WITHOUT_LLDB -.\" from FreeBSD: head/tools/build/options/WITHOUT_LLDB 289275 2015-10-14 00:23:31Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LLDB 289275 2015-10-14 00:23:31Z emaste Set to not build the LLDB debugger. .Pp It is a default setting on arm/arm, arm/armeb, arm/armv6, i386/i386, mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, pc98/i386, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITH_LLDB -.\" from FreeBSD: head/tools/build/options/WITH_LLDB 255722 2013-09-20 01:52:02Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_LLDB 255722 2013-09-20 01:52:02Z emaste Set to build the LLDB debugger. .Pp It is a default setting on amd64/amd64 and arm64/aarch64. .It Va WITHOUT_LLVM_LIBUNWIND -.\" from FreeBSD: head/tools/build/options/WITHOUT_LLVM_LIBUNWIND 293450 2016-01-09 00:42:07Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LLVM_LIBUNWIND 293450 2016-01-09 00:42:07Z emaste Set to use GCC's stack unwinder (instead of LLVM's libunwind). .Pp It is a default setting on amd64/amd64, arm/arm, arm/armeb, arm/armv6, i386/i386, mips/mipsel, mips/mips, mips/mips64el, mips/mips64, mips/mipsn32, pc98/i386, powerpc/powerpc, powerpc/powerpc64 and sparc64/sparc64. .It Va WITH_LLVM_LIBUNWIND -.\" from FreeBSD: head/tools/build/options/WITH_LLVM_LIBUNWIND 293450 2016-01-09 00:42:07Z emaste +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_LLVM_LIBUNWIND 293450 2016-01-09 00:42:07Z emaste Set to use LLVM's libunwind stack unwinder (instead of GCC's unwinder). .Pp It is a default setting on arm64/aarch64. .It Va WITHOUT_LOCALES -.\" from FreeBSD: head/tools/build/options/WITHOUT_LOCALES 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LOCALES 156932 2006-03-21 07:50:50Z ru Set to not build localization files; see .Xr locale 1 . .It Va WITHOUT_LOCATE -.\" from FreeBSD: head/tools/build/options/WITHOUT_LOCATE 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LOCATE 183242 2008-09-21 22:02:26Z sam Set to not build .Xr locate 1 and related programs. .It Va WITHOUT_LPR -.\" from FreeBSD: head/tools/build/options/WITHOUT_LPR 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LPR 156932 2006-03-21 07:50:50Z ru Set to not build .Xr lpr 1 and related programs. .It Va WITHOUT_LS_COLORS -.\" from FreeBSD: head/tools/build/options/WITHOUT_LS_COLORS 235660 2012-05-19 20:05:27Z marcel +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LS_COLORS 235660 2012-05-19 20:05:27Z marcel Set to build .Xr ls 1 without support for colors to distinguish file types. .It Va WITHOUT_LZMA_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_LZMA_SUPPORT 245171 2013-01-08 18:37:12Z obrien +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_LZMA_SUPPORT 245171 2013-01-08 18:37:12Z obrien Set to build some programs without optional lzma compression support. .It Va WITHOUT_MAIL -.\" from FreeBSD: head/tools/build/options/WITHOUT_MAIL 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MAIL 183242 2008-09-21 22:02:26Z sam Set to not build any mail support (MUA or MTA). When set, it also enforces the following options: .Pp @@ -1045,17 +1041,17 @@ When set, it also enforces the following .Va WITHOUT_SENDMAIL .El .It Va WITHOUT_MAILWRAPPER -.\" from FreeBSD: head/tools/build/options/WITHOUT_MAILWRAPPER 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MAILWRAPPER 156932 2006-03-21 07:50:50Z ru Set to not build the .Xr mailwrapper 8 MTA selector. .It Va WITHOUT_MAKE -.\" from FreeBSD: head/tools/build/options/WITHOUT_MAKE 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MAKE 183242 2008-09-21 22:02:26Z sam Set to not install .Xr make 1 and related support files. .It Va WITHOUT_MAN -.\" from FreeBSD: head/tools/build/options/WITHOUT_MAN 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MAN 156932 2006-03-21 07:50:50Z ru Set to not build manual pages. When set, the following options are also in effect: .Pp @@ -1066,18 +1062,18 @@ When set, the following options are also is set explicitly) .El .It Va WITHOUT_MANCOMPRESS -.\" from FreeBSD: head/tools/build/options/WITHOUT_MANCOMPRESS 266752 2014-05-27 15:52:27Z gjb +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MANCOMPRESS 266752 2014-05-27 15:52:27Z gjb Set to not to install compressed man pages. Only the uncompressed versions will be installed. .It Va WITHOUT_MANDOCDB -.\" from FreeBSD: head/tools/build/options/WITHOUT_MANDOCDB 283777 2015-05-30 17:41:37Z bapt +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MANDOCDB 283777 2015-05-30 17:41:37Z bapt Use the .Xr mandoc 1 version of .Xr makewhatis 8 database and utilities. .It Va WITHOUT_MAN_UTILS -.\" from FreeBSD: head/tools/build/options/WITHOUT_MAN_UTILS 208322 2010-05-20 00:07:21Z jkim +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_MAN_UTILS 208322 2010-05-20 00:07:21Z jkim Set to not build utilities for manual pages, .Xr apropos 1 , .Xr catman 1 , @@ -1087,7 +1083,7 @@ Set to not build utilities for manual pa .Xr manctl 8 , and related support files. .It Va WITH_META_MODE -.\" from FreeBSD: head/tools/build/options/WITH_META_MODE 301889 2016-06-14 16:20:25Z bdrewery +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_META_MODE 301889 2016-06-14 16:20:25Z bdrewery Creates .Xr make 1 meta files when building, which can provide a reliable incremental build when @@ -1141,33 +1137,25 @@ to .Pp Currently this also enforces .Va WITHOUT_SYSTEM_COMPILER . -When set, the following options are also in effect: -.Pp -.Bl -inset -compact -.It Va WITHOUT_SYSTEM_COMPILER -(unless -.Va WITH_SYSTEM_COMPILER -is set explicitly) -.El .Pp This must be set in the environment, make command line, or .Pa /etc/src-env.conf , not .Pa /etc/src.conf . .It Va WITH_NAND -.\" from FreeBSD: head/tools/build/options/WITH_NAND 235537 2012-05-17 10:11:18Z gber +.\" from FreeBSD: releng/11.0/tools/build/options/WITH_NAND 235537 2012-05-17 10:11:18Z gber Set to build the NAND Flash components. .It Va WITHOUT_NDIS -.\" from FreeBSD: head/tools/build/options/WITHOUT_NDIS 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NDIS 183242 2008-09-21 22:02:26Z sam Set to not build programs and libraries related to NDIS emulation support. .It Va WITHOUT_NETCAT -.\" from FreeBSD: head/tools/build/options/WITHOUT_NETCAT 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NETCAT 156932 2006-03-21 07:50:50Z ru Set to not build .Xr nc 1 utility. .It Va WITHOUT_NETGRAPH -.\" from FreeBSD: head/tools/build/options/WITHOUT_NETGRAPH 183242 2008-09-21 22:02:26Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NETGRAPH 183242 2008-09-21 22:02:26Z sam Set to not build applications to support .Xr netgraph 4 . When set, it also enforces the following options: @@ -1181,10 +1169,10 @@ When set, it also enforces the following .Va WITHOUT_NETGRAPH_SUPPORT .El .It Va WITHOUT_NETGRAPH_SUPPORT -.\" from FreeBSD: head/tools/build/options/WITHOUT_NETGRAPH_SUPPORT 183305 2008-09-23 16:11:15Z sam +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NETGRAPH_SUPPORT 183305 2008-09-23 16:11:15Z sam Set to build libraries, programs, and kernel modules without netgraph support. .It Va WITHOUT_NIS -.\" from FreeBSD: head/tools/build/options/WITHOUT_NIS 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NIS 156932 2006-03-21 07:50:50Z ru Set to not build .Xr NIS 8 support and related programs. @@ -1194,14 +1182,14 @@ and remove .Sq nis entries. .It Va WITHOUT_NLS -.\" from FreeBSD: head/tools/build/options/WITHOUT_NLS 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NLS 156932 2006-03-21 07:50:50Z ru Set to not build NLS catalogs. .It Va WITHOUT_NLS_CATALOGS -.\" from FreeBSD: head/tools/build/options/WITHOUT_NLS_CATALOGS 156932 2006-03-21 07:50:50Z ru +.\" from FreeBSD: releng/11.0/tools/build/options/WITHOUT_NLS_CATALOGS 156932 2006-03-21 07:50:50Z ru *** DIFF OUTPUT TRUNCATED AT 1000 LINES *** From owner-svn-src-releng@freebsd.org Thu Sep 22 15:55:31 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id D65E6BE69C9; Thu, 22 Sep 2016 15:55:31 +0000 (UTC) (envelope-from jkim@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 536D018E1; Thu, 22 Sep 2016 15:55:31 +0000 (UTC) (envelope-from jkim@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MFtUOk076335; Thu, 22 Sep 2016 15:55:30 GMT (envelope-from jkim@FreeBSD.org) Received: (from jkim@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MFtS6R076312; Thu, 22 Sep 2016 15:55:28 GMT (envelope-from jkim@FreeBSD.org) Message-Id: <201609221555.u8MFtS6R076312@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: jkim set sender to jkim@FreeBSD.org using -f From: Jung-uk Kim Date: Thu, 22 Sep 2016 15:55:28 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306198 - in releng/11.0: crypto/openssl crypto/openssl/apps crypto/openssl/crypto crypto/openssl/crypto/aes/asm crypto/openssl/crypto/asn1 crypto/openssl/crypto/bio crypto/openssl/cryp... X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 15:55:31 -0000 Author: jkim Date: Thu Sep 22 15:55:27 2016 New Revision: 306198 URL: https://svnweb.freebsd.org/changeset/base/306198 Log: MFS: r306195 Merge OpenSSL 1.0.2i. Approved by: re (gjb, implicit), so (delphij) Added: releng/11.0/crypto/openssl/doc/crypto/d2i_PrivateKey.pod - copied unchanged from r306195, stable/11/crypto/openssl/doc/crypto/d2i_PrivateKey.pod releng/11.0/crypto/openssl/ssl/bad_dtls_test.c - copied unchanged from r306195, stable/11/crypto/openssl/ssl/bad_dtls_test.c releng/11.0/crypto/openssl/ssl/dtlstest.c - copied unchanged from r306195, stable/11/crypto/openssl/ssl/dtlstest.c releng/11.0/secure/lib/libcrypto/man/d2i_PrivateKey.3 - copied unchanged from r306195, stable/11/secure/lib/libcrypto/man/d2i_PrivateKey.3 Modified: releng/11.0/crypto/openssl/CHANGES releng/11.0/crypto/openssl/CONTRIBUTING releng/11.0/crypto/openssl/Configure releng/11.0/crypto/openssl/Makefile releng/11.0/crypto/openssl/Makefile.org releng/11.0/crypto/openssl/Makefile.shared releng/11.0/crypto/openssl/NEWS releng/11.0/crypto/openssl/README releng/11.0/crypto/openssl/apps/CA.pl releng/11.0/crypto/openssl/apps/CA.pl.in releng/11.0/crypto/openssl/apps/apps.c releng/11.0/crypto/openssl/apps/apps.h releng/11.0/crypto/openssl/apps/ca.c releng/11.0/crypto/openssl/apps/dgst.c releng/11.0/crypto/openssl/apps/enc.c releng/11.0/crypto/openssl/apps/passwd.c releng/11.0/crypto/openssl/apps/pkcs12.c releng/11.0/crypto/openssl/apps/req.c releng/11.0/crypto/openssl/apps/s_apps.h releng/11.0/crypto/openssl/apps/s_cb.c releng/11.0/crypto/openssl/apps/s_client.c releng/11.0/crypto/openssl/apps/s_server.c releng/11.0/crypto/openssl/apps/speed.c releng/11.0/crypto/openssl/apps/srp.c releng/11.0/crypto/openssl/apps/verify.c releng/11.0/crypto/openssl/apps/x509.c releng/11.0/crypto/openssl/crypto/LPdir_unix.c releng/11.0/crypto/openssl/crypto/aes/asm/bsaes-armv7.pl releng/11.0/crypto/openssl/crypto/asn1/a_bytes.c releng/11.0/crypto/openssl/crypto/asn1/a_object.c releng/11.0/crypto/openssl/crypto/asn1/a_set.c releng/11.0/crypto/openssl/crypto/asn1/a_strex.c releng/11.0/crypto/openssl/crypto/asn1/a_strnid.c releng/11.0/crypto/openssl/crypto/asn1/ameth_lib.c releng/11.0/crypto/openssl/crypto/asn1/asn1_lib.c releng/11.0/crypto/openssl/crypto/asn1/asn_mime.c releng/11.0/crypto/openssl/crypto/asn1/bio_asn1.c releng/11.0/crypto/openssl/crypto/asn1/bio_ndef.c releng/11.0/crypto/openssl/crypto/asn1/charmap.pl releng/11.0/crypto/openssl/crypto/asn1/d2i_pr.c releng/11.0/crypto/openssl/crypto/asn1/f_enum.c releng/11.0/crypto/openssl/crypto/asn1/f_int.c releng/11.0/crypto/openssl/crypto/asn1/f_string.c releng/11.0/crypto/openssl/crypto/asn1/i2d_pr.c releng/11.0/crypto/openssl/crypto/asn1/p5_pbe.c releng/11.0/crypto/openssl/crypto/asn1/p5_pbev2.c releng/11.0/crypto/openssl/crypto/asn1/t_req.c releng/11.0/crypto/openssl/crypto/asn1/tasn_dec.c releng/11.0/crypto/openssl/crypto/asn1/tasn_enc.c releng/11.0/crypto/openssl/crypto/asn1/tasn_prn.c releng/11.0/crypto/openssl/crypto/asn1/tasn_utl.c releng/11.0/crypto/openssl/crypto/asn1/x_bignum.c releng/11.0/crypto/openssl/crypto/asn1/x_name.c releng/11.0/crypto/openssl/crypto/asn1/x_x509.c releng/11.0/crypto/openssl/crypto/bio/b_print.c releng/11.0/crypto/openssl/crypto/bio/bf_nbio.c releng/11.0/crypto/openssl/crypto/bio/bio.h releng/11.0/crypto/openssl/crypto/bio/bss_bio.c releng/11.0/crypto/openssl/crypto/bio/bss_file.c releng/11.0/crypto/openssl/crypto/bio/bss_rtcp.c releng/11.0/crypto/openssl/crypto/bn/asm/x86-mont.pl releng/11.0/crypto/openssl/crypto/bn/asm/x86_64-gcc.c releng/11.0/crypto/openssl/crypto/bn/asm/x86_64-mont.pl releng/11.0/crypto/openssl/crypto/bn/asm/x86_64-mont5.pl releng/11.0/crypto/openssl/crypto/bn/bn.h releng/11.0/crypto/openssl/crypto/bn/bn_div.c releng/11.0/crypto/openssl/crypto/bn/bn_lib.c releng/11.0/crypto/openssl/crypto/bn/bn_print.c releng/11.0/crypto/openssl/crypto/bn/bn_rand.c releng/11.0/crypto/openssl/crypto/bn/bn_word.c releng/11.0/crypto/openssl/crypto/bn/bntest.c releng/11.0/crypto/openssl/crypto/cms/cms_enc.c releng/11.0/crypto/openssl/crypto/cms/cms_ess.c releng/11.0/crypto/openssl/crypto/cms/cms_lib.c releng/11.0/crypto/openssl/crypto/cms/cms_pwri.c releng/11.0/crypto/openssl/crypto/comp/comp.h releng/11.0/crypto/openssl/crypto/conf/conf_def.h releng/11.0/crypto/openssl/crypto/conf/conf_mod.c releng/11.0/crypto/openssl/crypto/conf/keysets.pl releng/11.0/crypto/openssl/crypto/des/asm/dest4-sparcv9.pl releng/11.0/crypto/openssl/crypto/des/des.c releng/11.0/crypto/openssl/crypto/des/enc_writ.c releng/11.0/crypto/openssl/crypto/dh/dh_ameth.c releng/11.0/crypto/openssl/crypto/dsa/dsa_ameth.c releng/11.0/crypto/openssl/crypto/dsa/dsa_gen.c releng/11.0/crypto/openssl/crypto/dsa/dsa_ossl.c releng/11.0/crypto/openssl/crypto/ec/Makefile releng/11.0/crypto/openssl/crypto/ec/asm/ecp_nistz256-x86_64.pl releng/11.0/crypto/openssl/crypto/ec/ec_ameth.c releng/11.0/crypto/openssl/crypto/ec/ec_key.c releng/11.0/crypto/openssl/crypto/ec/ecp_nistz256.c releng/11.0/crypto/openssl/crypto/engine/eng_cryptodev.c releng/11.0/crypto/openssl/crypto/evp/bio_enc.c releng/11.0/crypto/openssl/crypto/evp/bio_ok.c releng/11.0/crypto/openssl/crypto/evp/c_all.c releng/11.0/crypto/openssl/crypto/evp/digest.c releng/11.0/crypto/openssl/crypto/evp/e_rc4_hmac_md5.c releng/11.0/crypto/openssl/crypto/evp/e_seed.c releng/11.0/crypto/openssl/crypto/evp/evp_enc.c releng/11.0/crypto/openssl/crypto/evp/evp_test.c releng/11.0/crypto/openssl/crypto/evp/openbsd_hw.c releng/11.0/crypto/openssl/crypto/evp/p_lib.c releng/11.0/crypto/openssl/crypto/evp/pmeth_gn.c releng/11.0/crypto/openssl/crypto/evp/pmeth_lib.c releng/11.0/crypto/openssl/crypto/hmac/hmac.c releng/11.0/crypto/openssl/crypto/jpake/jpake.c releng/11.0/crypto/openssl/crypto/lhash/lhash.c releng/11.0/crypto/openssl/crypto/md2/md2_dgst.c releng/11.0/crypto/openssl/crypto/md32_common.h releng/11.0/crypto/openssl/crypto/mdc2/mdc2dgst.c releng/11.0/crypto/openssl/crypto/mem.c releng/11.0/crypto/openssl/crypto/mem_clr.c releng/11.0/crypto/openssl/crypto/modes/asm/ghash-sparcv9.pl releng/11.0/crypto/openssl/crypto/o_init.c releng/11.0/crypto/openssl/crypto/o_time.c releng/11.0/crypto/openssl/crypto/objects/o_names.c releng/11.0/crypto/openssl/crypto/ocsp/ocsp_cl.c releng/11.0/crypto/openssl/crypto/ocsp/ocsp_ext.c releng/11.0/crypto/openssl/crypto/ocsp/ocsp_lib.c releng/11.0/crypto/openssl/crypto/opensslv.h releng/11.0/crypto/openssl/crypto/ossl_typ.h releng/11.0/crypto/openssl/crypto/pem/pem.h releng/11.0/crypto/openssl/crypto/pem/pem_err.c releng/11.0/crypto/openssl/crypto/pem/pem_lib.c releng/11.0/crypto/openssl/crypto/pem/pvkfmt.c releng/11.0/crypto/openssl/crypto/perlasm/sparcv9_modes.pl releng/11.0/crypto/openssl/crypto/pkcs12/p12_mutl.c releng/11.0/crypto/openssl/crypto/pkcs12/p12_npas.c releng/11.0/crypto/openssl/crypto/pkcs12/p12_utl.c releng/11.0/crypto/openssl/crypto/pkcs12/pkcs12.h releng/11.0/crypto/openssl/crypto/pkcs7/pk7_doit.c releng/11.0/crypto/openssl/crypto/rand/md_rand.c releng/11.0/crypto/openssl/crypto/rand/rand_unix.c releng/11.0/crypto/openssl/crypto/rand/randfile.c releng/11.0/crypto/openssl/crypto/rsa/rsa_ameth.c releng/11.0/crypto/openssl/crypto/rsa/rsa_chk.c releng/11.0/crypto/openssl/crypto/rsa/rsa_lib.c releng/11.0/crypto/openssl/crypto/rsa/rsa_pmeth.c releng/11.0/crypto/openssl/crypto/sha/asm/sha1-x86_64.pl releng/11.0/crypto/openssl/crypto/sparccpuid.S releng/11.0/crypto/openssl/crypto/srp/srp_lib.c releng/11.0/crypto/openssl/crypto/srp/srp_vfy.c releng/11.0/crypto/openssl/crypto/ts/ts.h releng/11.0/crypto/openssl/crypto/ts/ts_lib.c releng/11.0/crypto/openssl/crypto/ts/ts_rsp_verify.c releng/11.0/crypto/openssl/crypto/ui/ui_lib.c releng/11.0/crypto/openssl/crypto/whrlpool/wp_dgst.c releng/11.0/crypto/openssl/crypto/x509/by_dir.c releng/11.0/crypto/openssl/crypto/x509/x509.h releng/11.0/crypto/openssl/crypto/x509/x509_att.c releng/11.0/crypto/openssl/crypto/x509/x509_err.c releng/11.0/crypto/openssl/crypto/x509/x509_obj.c releng/11.0/crypto/openssl/crypto/x509/x509_r2x.c releng/11.0/crypto/openssl/crypto/x509/x509_txt.c releng/11.0/crypto/openssl/crypto/x509/x509_vfy.c releng/11.0/crypto/openssl/crypto/x509/x509_vfy.h releng/11.0/crypto/openssl/crypto/x509/x509spki.c releng/11.0/crypto/openssl/crypto/x509v3/v3_addr.c releng/11.0/crypto/openssl/crypto/x509v3/v3_alt.c releng/11.0/crypto/openssl/crypto/x509v3/v3_conf.c releng/11.0/crypto/openssl/doc/apps/cms.pod releng/11.0/crypto/openssl/doc/apps/s_client.pod releng/11.0/crypto/openssl/doc/apps/s_server.pod releng/11.0/crypto/openssl/doc/apps/smime.pod releng/11.0/crypto/openssl/doc/apps/verify.pod releng/11.0/crypto/openssl/doc/apps/x509.pod releng/11.0/crypto/openssl/doc/apps/x509v3_config.pod releng/11.0/crypto/openssl/doc/crypto/BIO_s_bio.pod releng/11.0/crypto/openssl/doc/crypto/BN_bn2bin.pod releng/11.0/crypto/openssl/doc/crypto/BN_rand.pod releng/11.0/crypto/openssl/doc/crypto/EVP_EncryptInit.pod releng/11.0/crypto/openssl/doc/crypto/EVP_PKEY_cmp.pod releng/11.0/crypto/openssl/doc/crypto/OBJ_nid2obj.pod releng/11.0/crypto/openssl/doc/crypto/OPENSSL_config.pod releng/11.0/crypto/openssl/doc/crypto/OPENSSL_ia32cap.pod releng/11.0/crypto/openssl/doc/crypto/X509_verify_cert.pod releng/11.0/crypto/openssl/doc/crypto/d2i_X509.pod releng/11.0/crypto/openssl/doc/crypto/hmac.pod releng/11.0/crypto/openssl/doc/crypto/rand.pod releng/11.0/crypto/openssl/doc/crypto/ui.pod releng/11.0/crypto/openssl/engines/ccgost/gost2001.c releng/11.0/crypto/openssl/engines/ccgost/gost2001_keyx.c releng/11.0/crypto/openssl/engines/ccgost/gost94_keyx.c releng/11.0/crypto/openssl/engines/ccgost/gost_ameth.c releng/11.0/crypto/openssl/engines/ccgost/gost_pmeth.c releng/11.0/crypto/openssl/engines/e_4758cca.c releng/11.0/crypto/openssl/engines/e_aep.c releng/11.0/crypto/openssl/engines/e_capi.c releng/11.0/crypto/openssl/engines/e_chil.c releng/11.0/crypto/openssl/ssl/Makefile releng/11.0/crypto/openssl/ssl/d1_both.c releng/11.0/crypto/openssl/ssl/d1_clnt.c releng/11.0/crypto/openssl/ssl/d1_lib.c releng/11.0/crypto/openssl/ssl/d1_pkt.c releng/11.0/crypto/openssl/ssl/d1_srvr.c releng/11.0/crypto/openssl/ssl/s23_clnt.c releng/11.0/crypto/openssl/ssl/s2_clnt.c releng/11.0/crypto/openssl/ssl/s2_srvr.c releng/11.0/crypto/openssl/ssl/s3_both.c releng/11.0/crypto/openssl/ssl/s3_clnt.c releng/11.0/crypto/openssl/ssl/s3_enc.c releng/11.0/crypto/openssl/ssl/s3_lib.c releng/11.0/crypto/openssl/ssl/s3_pkt.c releng/11.0/crypto/openssl/ssl/s3_srvr.c releng/11.0/crypto/openssl/ssl/ssl.h releng/11.0/crypto/openssl/ssl/ssl_asn1.c releng/11.0/crypto/openssl/ssl/ssl_ciph.c releng/11.0/crypto/openssl/ssl/ssl_err.c releng/11.0/crypto/openssl/ssl/ssl_lib.c releng/11.0/crypto/openssl/ssl/ssl_locl.h releng/11.0/crypto/openssl/ssl/ssl_rsa.c releng/11.0/crypto/openssl/ssl/ssl_sess.c releng/11.0/crypto/openssl/ssl/ssltest.c releng/11.0/crypto/openssl/ssl/sslv2conftest.c releng/11.0/crypto/openssl/ssl/t1_enc.c releng/11.0/crypto/openssl/ssl/t1_lib.c releng/11.0/crypto/openssl/util/mk1mf.pl releng/11.0/crypto/openssl/util/mkerr.pl releng/11.0/crypto/openssl/util/ssleay.num releng/11.0/secure/lib/libcrypto/Makefile.inc releng/11.0/secure/lib/libcrypto/Makefile.man releng/11.0/secure/lib/libcrypto/amd64/ecp_nistz256-x86_64.S releng/11.0/secure/lib/libcrypto/amd64/sha1-x86_64.S releng/11.0/secure/lib/libcrypto/amd64/x86_64-mont.S releng/11.0/secure/lib/libcrypto/amd64/x86_64-mont5.S releng/11.0/secure/lib/libcrypto/i386/x86-mont.S releng/11.0/secure/lib/libcrypto/man/ASN1_OBJECT_new.3 releng/11.0/secure/lib/libcrypto/man/ASN1_STRING_length.3 releng/11.0/secure/lib/libcrypto/man/ASN1_STRING_new.3 releng/11.0/secure/lib/libcrypto/man/ASN1_STRING_print_ex.3 releng/11.0/secure/lib/libcrypto/man/ASN1_TIME_set.3 releng/11.0/secure/lib/libcrypto/man/ASN1_generate_nconf.3 releng/11.0/secure/lib/libcrypto/man/BIO_ctrl.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_base64.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_buffer.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_cipher.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_md.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_null.3 releng/11.0/secure/lib/libcrypto/man/BIO_f_ssl.3 releng/11.0/secure/lib/libcrypto/man/BIO_find_type.3 releng/11.0/secure/lib/libcrypto/man/BIO_new.3 releng/11.0/secure/lib/libcrypto/man/BIO_new_CMS.3 releng/11.0/secure/lib/libcrypto/man/BIO_push.3 releng/11.0/secure/lib/libcrypto/man/BIO_read.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_accept.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_bio.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_connect.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_fd.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_file.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_mem.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_null.3 releng/11.0/secure/lib/libcrypto/man/BIO_s_socket.3 releng/11.0/secure/lib/libcrypto/man/BIO_set_callback.3 releng/11.0/secure/lib/libcrypto/man/BIO_should_retry.3 releng/11.0/secure/lib/libcrypto/man/BN_BLINDING_new.3 releng/11.0/secure/lib/libcrypto/man/BN_CTX_new.3 releng/11.0/secure/lib/libcrypto/man/BN_CTX_start.3 releng/11.0/secure/lib/libcrypto/man/BN_add.3 releng/11.0/secure/lib/libcrypto/man/BN_add_word.3 releng/11.0/secure/lib/libcrypto/man/BN_bn2bin.3 releng/11.0/secure/lib/libcrypto/man/BN_cmp.3 releng/11.0/secure/lib/libcrypto/man/BN_copy.3 releng/11.0/secure/lib/libcrypto/man/BN_generate_prime.3 releng/11.0/secure/lib/libcrypto/man/BN_mod_inverse.3 releng/11.0/secure/lib/libcrypto/man/BN_mod_mul_montgomery.3 releng/11.0/secure/lib/libcrypto/man/BN_mod_mul_reciprocal.3 releng/11.0/secure/lib/libcrypto/man/BN_new.3 releng/11.0/secure/lib/libcrypto/man/BN_num_bytes.3 releng/11.0/secure/lib/libcrypto/man/BN_rand.3 releng/11.0/secure/lib/libcrypto/man/BN_set_bit.3 releng/11.0/secure/lib/libcrypto/man/BN_swap.3 releng/11.0/secure/lib/libcrypto/man/BN_zero.3 releng/11.0/secure/lib/libcrypto/man/CMS_add0_cert.3 releng/11.0/secure/lib/libcrypto/man/CMS_add1_recipient_cert.3 releng/11.0/secure/lib/libcrypto/man/CMS_add1_signer.3 releng/11.0/secure/lib/libcrypto/man/CMS_compress.3 releng/11.0/secure/lib/libcrypto/man/CMS_decrypt.3 releng/11.0/secure/lib/libcrypto/man/CMS_encrypt.3 releng/11.0/secure/lib/libcrypto/man/CMS_final.3 releng/11.0/secure/lib/libcrypto/man/CMS_get0_RecipientInfos.3 releng/11.0/secure/lib/libcrypto/man/CMS_get0_SignerInfos.3 releng/11.0/secure/lib/libcrypto/man/CMS_get0_type.3 releng/11.0/secure/lib/libcrypto/man/CMS_get1_ReceiptRequest.3 releng/11.0/secure/lib/libcrypto/man/CMS_sign.3 releng/11.0/secure/lib/libcrypto/man/CMS_sign_receipt.3 releng/11.0/secure/lib/libcrypto/man/CMS_uncompress.3 releng/11.0/secure/lib/libcrypto/man/CMS_verify.3 releng/11.0/secure/lib/libcrypto/man/CMS_verify_receipt.3 releng/11.0/secure/lib/libcrypto/man/CONF_modules_free.3 releng/11.0/secure/lib/libcrypto/man/CONF_modules_load_file.3 releng/11.0/secure/lib/libcrypto/man/CRYPTO_set_ex_data.3 releng/11.0/secure/lib/libcrypto/man/DH_generate_key.3 releng/11.0/secure/lib/libcrypto/man/DH_generate_parameters.3 releng/11.0/secure/lib/libcrypto/man/DH_get_ex_new_index.3 releng/11.0/secure/lib/libcrypto/man/DH_new.3 releng/11.0/secure/lib/libcrypto/man/DH_set_method.3 releng/11.0/secure/lib/libcrypto/man/DH_size.3 releng/11.0/secure/lib/libcrypto/man/DSA_SIG_new.3 releng/11.0/secure/lib/libcrypto/man/DSA_do_sign.3 releng/11.0/secure/lib/libcrypto/man/DSA_dup_DH.3 releng/11.0/secure/lib/libcrypto/man/DSA_generate_key.3 releng/11.0/secure/lib/libcrypto/man/DSA_generate_parameters.3 releng/11.0/secure/lib/libcrypto/man/DSA_get_ex_new_index.3 releng/11.0/secure/lib/libcrypto/man/DSA_new.3 releng/11.0/secure/lib/libcrypto/man/DSA_set_method.3 releng/11.0/secure/lib/libcrypto/man/DSA_sign.3 releng/11.0/secure/lib/libcrypto/man/DSA_size.3 releng/11.0/secure/lib/libcrypto/man/EC_GFp_simple_method.3 releng/11.0/secure/lib/libcrypto/man/EC_GROUP_copy.3 releng/11.0/secure/lib/libcrypto/man/EC_GROUP_new.3 releng/11.0/secure/lib/libcrypto/man/EC_KEY_new.3 releng/11.0/secure/lib/libcrypto/man/EC_POINT_add.3 releng/11.0/secure/lib/libcrypto/man/EC_POINT_new.3 releng/11.0/secure/lib/libcrypto/man/ERR_GET_LIB.3 releng/11.0/secure/lib/libcrypto/man/ERR_clear_error.3 releng/11.0/secure/lib/libcrypto/man/ERR_error_string.3 releng/11.0/secure/lib/libcrypto/man/ERR_get_error.3 releng/11.0/secure/lib/libcrypto/man/ERR_load_crypto_strings.3 releng/11.0/secure/lib/libcrypto/man/ERR_load_strings.3 releng/11.0/secure/lib/libcrypto/man/ERR_print_errors.3 releng/11.0/secure/lib/libcrypto/man/ERR_put_error.3 releng/11.0/secure/lib/libcrypto/man/ERR_remove_state.3 releng/11.0/secure/lib/libcrypto/man/ERR_set_mark.3 releng/11.0/secure/lib/libcrypto/man/EVP_BytesToKey.3 releng/11.0/secure/lib/libcrypto/man/EVP_DigestInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_DigestSignInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_DigestVerifyInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_EncodeInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_EncryptInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_OpenInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_CTX_ctrl.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_CTX_new.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_cmp.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_decrypt.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_derive.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_encrypt.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_get_default_digest.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_keygen.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_new.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_print_private.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_set1_RSA.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_sign.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_verify.3 releng/11.0/secure/lib/libcrypto/man/EVP_PKEY_verify_recover.3 releng/11.0/secure/lib/libcrypto/man/EVP_SealInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_SignInit.3 releng/11.0/secure/lib/libcrypto/man/EVP_VerifyInit.3 releng/11.0/secure/lib/libcrypto/man/OBJ_nid2obj.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_Applink.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_VERSION_NUMBER.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_config.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_ia32cap.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_instrument_bus.3 releng/11.0/secure/lib/libcrypto/man/OPENSSL_load_builtin_modules.3 releng/11.0/secure/lib/libcrypto/man/OpenSSL_add_all_algorithms.3 releng/11.0/secure/lib/libcrypto/man/PEM_write_bio_CMS_stream.3 releng/11.0/secure/lib/libcrypto/man/PEM_write_bio_PKCS7_stream.3 releng/11.0/secure/lib/libcrypto/man/PKCS12_create.3 releng/11.0/secure/lib/libcrypto/man/PKCS12_parse.3 releng/11.0/secure/lib/libcrypto/man/PKCS7_decrypt.3 releng/11.0/secure/lib/libcrypto/man/PKCS7_encrypt.3 releng/11.0/secure/lib/libcrypto/man/PKCS7_sign.3 releng/11.0/secure/lib/libcrypto/man/PKCS7_sign_add_signer.3 releng/11.0/secure/lib/libcrypto/man/PKCS7_verify.3 releng/11.0/secure/lib/libcrypto/man/RAND_add.3 releng/11.0/secure/lib/libcrypto/man/RAND_bytes.3 releng/11.0/secure/lib/libcrypto/man/RAND_cleanup.3 releng/11.0/secure/lib/libcrypto/man/RAND_egd.3 releng/11.0/secure/lib/libcrypto/man/RAND_load_file.3 releng/11.0/secure/lib/libcrypto/man/RAND_set_rand_method.3 releng/11.0/secure/lib/libcrypto/man/RSA_blinding_on.3 releng/11.0/secure/lib/libcrypto/man/RSA_check_key.3 releng/11.0/secure/lib/libcrypto/man/RSA_generate_key.3 releng/11.0/secure/lib/libcrypto/man/RSA_get_ex_new_index.3 releng/11.0/secure/lib/libcrypto/man/RSA_new.3 releng/11.0/secure/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 releng/11.0/secure/lib/libcrypto/man/RSA_print.3 releng/11.0/secure/lib/libcrypto/man/RSA_private_encrypt.3 releng/11.0/secure/lib/libcrypto/man/RSA_public_encrypt.3 releng/11.0/secure/lib/libcrypto/man/RSA_set_method.3 releng/11.0/secure/lib/libcrypto/man/RSA_sign.3 releng/11.0/secure/lib/libcrypto/man/RSA_sign_ASN1_OCTET_STRING.3 releng/11.0/secure/lib/libcrypto/man/RSA_size.3 releng/11.0/secure/lib/libcrypto/man/SMIME_read_CMS.3 releng/11.0/secure/lib/libcrypto/man/SMIME_read_PKCS7.3 releng/11.0/secure/lib/libcrypto/man/SMIME_write_CMS.3 releng/11.0/secure/lib/libcrypto/man/SMIME_write_PKCS7.3 releng/11.0/secure/lib/libcrypto/man/X509_NAME_ENTRY_get_object.3 releng/11.0/secure/lib/libcrypto/man/X509_NAME_add_entry_by_txt.3 releng/11.0/secure/lib/libcrypto/man/X509_NAME_get_index_by_NID.3 releng/11.0/secure/lib/libcrypto/man/X509_NAME_print_ex.3 releng/11.0/secure/lib/libcrypto/man/X509_STORE_CTX_get_error.3 releng/11.0/secure/lib/libcrypto/man/X509_STORE_CTX_get_ex_new_index.3 releng/11.0/secure/lib/libcrypto/man/X509_STORE_CTX_new.3 releng/11.0/secure/lib/libcrypto/man/X509_STORE_CTX_set_verify_cb.3 releng/11.0/secure/lib/libcrypto/man/X509_STORE_set_verify_cb_func.3 releng/11.0/secure/lib/libcrypto/man/X509_VERIFY_PARAM_set_flags.3 releng/11.0/secure/lib/libcrypto/man/X509_check_host.3 releng/11.0/secure/lib/libcrypto/man/X509_new.3 releng/11.0/secure/lib/libcrypto/man/X509_verify_cert.3 releng/11.0/secure/lib/libcrypto/man/bio.3 releng/11.0/secure/lib/libcrypto/man/blowfish.3 releng/11.0/secure/lib/libcrypto/man/bn.3 releng/11.0/secure/lib/libcrypto/man/bn_internal.3 releng/11.0/secure/lib/libcrypto/man/buffer.3 releng/11.0/secure/lib/libcrypto/man/crypto.3 releng/11.0/secure/lib/libcrypto/man/d2i_ASN1_OBJECT.3 releng/11.0/secure/lib/libcrypto/man/d2i_CMS_ContentInfo.3 releng/11.0/secure/lib/libcrypto/man/d2i_DHparams.3 releng/11.0/secure/lib/libcrypto/man/d2i_DSAPublicKey.3 releng/11.0/secure/lib/libcrypto/man/d2i_ECPKParameters.3 releng/11.0/secure/lib/libcrypto/man/d2i_ECPrivateKey.3 releng/11.0/secure/lib/libcrypto/man/d2i_PKCS8PrivateKey.3 releng/11.0/secure/lib/libcrypto/man/d2i_RSAPublicKey.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509_ALGOR.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509_CRL.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509_NAME.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509_REQ.3 releng/11.0/secure/lib/libcrypto/man/d2i_X509_SIG.3 releng/11.0/secure/lib/libcrypto/man/des.3 releng/11.0/secure/lib/libcrypto/man/dh.3 releng/11.0/secure/lib/libcrypto/man/dsa.3 releng/11.0/secure/lib/libcrypto/man/ec.3 releng/11.0/secure/lib/libcrypto/man/ecdsa.3 releng/11.0/secure/lib/libcrypto/man/engine.3 releng/11.0/secure/lib/libcrypto/man/err.3 releng/11.0/secure/lib/libcrypto/man/evp.3 releng/11.0/secure/lib/libcrypto/man/hmac.3 releng/11.0/secure/lib/libcrypto/man/i2d_CMS_bio_stream.3 releng/11.0/secure/lib/libcrypto/man/i2d_PKCS7_bio_stream.3 releng/11.0/secure/lib/libcrypto/man/lh_stats.3 releng/11.0/secure/lib/libcrypto/man/lhash.3 releng/11.0/secure/lib/libcrypto/man/md5.3 releng/11.0/secure/lib/libcrypto/man/mdc2.3 releng/11.0/secure/lib/libcrypto/man/pem.3 releng/11.0/secure/lib/libcrypto/man/rand.3 releng/11.0/secure/lib/libcrypto/man/rc4.3 releng/11.0/secure/lib/libcrypto/man/ripemd.3 releng/11.0/secure/lib/libcrypto/man/rsa.3 releng/11.0/secure/lib/libcrypto/man/sha.3 releng/11.0/secure/lib/libcrypto/man/threads.3 releng/11.0/secure/lib/libcrypto/man/ui.3 releng/11.0/secure/lib/libcrypto/man/ui_compat.3 releng/11.0/secure/lib/libcrypto/man/x509.3 releng/11.0/secure/lib/libssl/man/SSL_CIPHER_get_name.3 releng/11.0/secure/lib/libssl/man/SSL_COMP_add_compression_method.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_CTX_new.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_CTX_set1_prefix.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_CTX_set_flags.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_CTX_set_ssl_ctx.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_cmd.3 releng/11.0/secure/lib/libssl/man/SSL_CONF_cmd_argv.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_add1_chain_cert.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_add_extra_chain_cert.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_add_session.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_ctrl.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_flush_sessions.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_free.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_get0_param.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_get_ex_new_index.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_get_verify_mode.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_load_verify_locations.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_new.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_sess_number.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_sess_set_cache_size.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_sess_set_get_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_sessions.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set1_curves.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set1_verify_cert_store.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_alpn_select_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_cert_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_cert_store.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_cert_verify_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_cipher_list.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_client_CA_list.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_client_cert_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_custom_cli_ext.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_default_passwd_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_generate_session_id.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_info_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_max_cert_list.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_mode.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_msg_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_options.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_psk_client_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_quiet_shutdown.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_read_ahead.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_session_cache_mode.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_session_id_context.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_ssl_version.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_timeout.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_tlsext_status_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_tlsext_ticket_key_cb.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_tmp_dh_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_tmp_rsa_callback.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_set_verify.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_use_certificate.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_use_psk_identity_hint.3 releng/11.0/secure/lib/libssl/man/SSL_CTX_use_serverinfo.3 releng/11.0/secure/lib/libssl/man/SSL_SESSION_free.3 releng/11.0/secure/lib/libssl/man/SSL_SESSION_get_ex_new_index.3 releng/11.0/secure/lib/libssl/man/SSL_SESSION_get_time.3 releng/11.0/secure/lib/libssl/man/SSL_accept.3 releng/11.0/secure/lib/libssl/man/SSL_alert_type_string.3 releng/11.0/secure/lib/libssl/man/SSL_check_chain.3 releng/11.0/secure/lib/libssl/man/SSL_clear.3 releng/11.0/secure/lib/libssl/man/SSL_connect.3 releng/11.0/secure/lib/libssl/man/SSL_do_handshake.3 releng/11.0/secure/lib/libssl/man/SSL_free.3 releng/11.0/secure/lib/libssl/man/SSL_get_SSL_CTX.3 releng/11.0/secure/lib/libssl/man/SSL_get_ciphers.3 releng/11.0/secure/lib/libssl/man/SSL_get_client_CA_list.3 releng/11.0/secure/lib/libssl/man/SSL_get_current_cipher.3 releng/11.0/secure/lib/libssl/man/SSL_get_default_timeout.3 releng/11.0/secure/lib/libssl/man/SSL_get_error.3 releng/11.0/secure/lib/libssl/man/SSL_get_ex_data_X509_STORE_CTX_idx.3 releng/11.0/secure/lib/libssl/man/SSL_get_ex_new_index.3 releng/11.0/secure/lib/libssl/man/SSL_get_fd.3 releng/11.0/secure/lib/libssl/man/SSL_get_peer_cert_chain.3 releng/11.0/secure/lib/libssl/man/SSL_get_peer_certificate.3 releng/11.0/secure/lib/libssl/man/SSL_get_psk_identity.3 releng/11.0/secure/lib/libssl/man/SSL_get_rbio.3 releng/11.0/secure/lib/libssl/man/SSL_get_session.3 releng/11.0/secure/lib/libssl/man/SSL_get_verify_result.3 releng/11.0/secure/lib/libssl/man/SSL_get_version.3 releng/11.0/secure/lib/libssl/man/SSL_library_init.3 releng/11.0/secure/lib/libssl/man/SSL_load_client_CA_file.3 releng/11.0/secure/lib/libssl/man/SSL_new.3 releng/11.0/secure/lib/libssl/man/SSL_pending.3 releng/11.0/secure/lib/libssl/man/SSL_read.3 releng/11.0/secure/lib/libssl/man/SSL_rstate_string.3 releng/11.0/secure/lib/libssl/man/SSL_session_reused.3 releng/11.0/secure/lib/libssl/man/SSL_set_bio.3 releng/11.0/secure/lib/libssl/man/SSL_set_connect_state.3 releng/11.0/secure/lib/libssl/man/SSL_set_fd.3 releng/11.0/secure/lib/libssl/man/SSL_set_session.3 releng/11.0/secure/lib/libssl/man/SSL_set_shutdown.3 releng/11.0/secure/lib/libssl/man/SSL_set_verify_result.3 releng/11.0/secure/lib/libssl/man/SSL_shutdown.3 releng/11.0/secure/lib/libssl/man/SSL_state_string.3 releng/11.0/secure/lib/libssl/man/SSL_want.3 releng/11.0/secure/lib/libssl/man/SSL_write.3 releng/11.0/secure/lib/libssl/man/d2i_SSL_SESSION.3 releng/11.0/secure/lib/libssl/man/ssl.3 releng/11.0/secure/usr.bin/openssl/man/CA.pl.1 releng/11.0/secure/usr.bin/openssl/man/asn1parse.1 releng/11.0/secure/usr.bin/openssl/man/c_rehash.1 releng/11.0/secure/usr.bin/openssl/man/ca.1 releng/11.0/secure/usr.bin/openssl/man/ciphers.1 releng/11.0/secure/usr.bin/openssl/man/cms.1 releng/11.0/secure/usr.bin/openssl/man/crl.1 releng/11.0/secure/usr.bin/openssl/man/crl2pkcs7.1 releng/11.0/secure/usr.bin/openssl/man/dgst.1 releng/11.0/secure/usr.bin/openssl/man/dhparam.1 releng/11.0/secure/usr.bin/openssl/man/dsa.1 releng/11.0/secure/usr.bin/openssl/man/dsaparam.1 releng/11.0/secure/usr.bin/openssl/man/ec.1 releng/11.0/secure/usr.bin/openssl/man/ecparam.1 releng/11.0/secure/usr.bin/openssl/man/enc.1 releng/11.0/secure/usr.bin/openssl/man/errstr.1 releng/11.0/secure/usr.bin/openssl/man/gendsa.1 releng/11.0/secure/usr.bin/openssl/man/genpkey.1 releng/11.0/secure/usr.bin/openssl/man/genrsa.1 releng/11.0/secure/usr.bin/openssl/man/nseq.1 releng/11.0/secure/usr.bin/openssl/man/ocsp.1 releng/11.0/secure/usr.bin/openssl/man/openssl.1 releng/11.0/secure/usr.bin/openssl/man/passwd.1 releng/11.0/secure/usr.bin/openssl/man/pkcs12.1 releng/11.0/secure/usr.bin/openssl/man/pkcs7.1 releng/11.0/secure/usr.bin/openssl/man/pkcs8.1 releng/11.0/secure/usr.bin/openssl/man/pkey.1 releng/11.0/secure/usr.bin/openssl/man/pkeyparam.1 releng/11.0/secure/usr.bin/openssl/man/pkeyutl.1 releng/11.0/secure/usr.bin/openssl/man/rand.1 releng/11.0/secure/usr.bin/openssl/man/req.1 releng/11.0/secure/usr.bin/openssl/man/rsa.1 releng/11.0/secure/usr.bin/openssl/man/rsautl.1 releng/11.0/secure/usr.bin/openssl/man/s_client.1 releng/11.0/secure/usr.bin/openssl/man/s_server.1 releng/11.0/secure/usr.bin/openssl/man/s_time.1 releng/11.0/secure/usr.bin/openssl/man/sess_id.1 releng/11.0/secure/usr.bin/openssl/man/smime.1 releng/11.0/secure/usr.bin/openssl/man/speed.1 releng/11.0/secure/usr.bin/openssl/man/spkac.1 releng/11.0/secure/usr.bin/openssl/man/ts.1 releng/11.0/secure/usr.bin/openssl/man/tsget.1 releng/11.0/secure/usr.bin/openssl/man/verify.1 releng/11.0/secure/usr.bin/openssl/man/version.1 releng/11.0/secure/usr.bin/openssl/man/x509.1 releng/11.0/secure/usr.bin/openssl/man/x509v3_config.1 Directory Properties: releng/11.0/ (props changed) Modified: releng/11.0/crypto/openssl/CHANGES ============================================================================== --- releng/11.0/crypto/openssl/CHANGES Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/CHANGES Thu Sep 22 15:55:27 2016 (r306198) @@ -2,6 +2,166 @@ OpenSSL CHANGES _______________ + Changes between 1.0.2h and 1.0.2i [22 Sep 2016] + + *) OCSP Status Request extension unbounded memory growth + + A malicious client can send an excessively large OCSP Status Request + extension. If that client continually requests renegotiation, sending a + large OCSP Status Request extension each time, then there will be unbounded + memory growth on the server. This will eventually lead to a Denial Of + Service attack through memory exhaustion. Servers with a default + configuration are vulnerable even if they do not support OCSP. Builds using + the "no-ocsp" build time option are not affected. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-6304) + [Matt Caswell] + + *) In order to mitigate the SWEET32 attack, the DES ciphers were moved from + HIGH to MEDIUM. + + This issue was reported to OpenSSL Karthikeyan Bhargavan and Gaetan + Leurent (INRIA) + (CVE-2016-2183) + [Rich Salz] + + *) OOB write in MDC2_Update() + + An overflow can occur in MDC2_Update() either if called directly or + through the EVP_DigestUpdate() function using MDC2. If an attacker + is able to supply very large amounts of input data after a previous + call to EVP_EncryptUpdate() with a partial block then a length check + can overflow resulting in a heap corruption. + + The amount of data needed is comparable to SIZE_MAX which is impractical + on most platforms. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-6303) + [Stephen Henson] + + *) Malformed SHA512 ticket DoS + + If a server uses SHA512 for TLS session ticket HMAC it is vulnerable to a + DoS attack where a malformed ticket will result in an OOB read which will + ultimately crash. + + The use of SHA512 in TLS session tickets is comparatively rare as it requires + a custom server callback and ticket lookup mechanism. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-6302) + [Stephen Henson] + + *) OOB write in BN_bn2dec() + + The function BN_bn2dec() does not check the return value of BN_div_word(). + This can cause an OOB write if an application uses this function with an + overly large BIGNUM. This could be a problem if an overly large certificate + or CRL is printed out from an untrusted source. TLS is not affected because + record limits will reject an oversized certificate before it is parsed. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-2182) + [Stephen Henson] + + *) OOB read in TS_OBJ_print_bio() + + The function TS_OBJ_print_bio() misuses OBJ_obj2txt(): the return value is + the total length the OID text representation would use and not the amount + of data written. This will result in OOB reads when large OIDs are + presented. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-2180) + [Stephen Henson] + + *) Pointer arithmetic undefined behaviour + + Avoid some undefined pointer arithmetic + + A common idiom in the codebase is to check limits in the following manner: + "p + len > limit" + + Where "p" points to some malloc'd data of SIZE bytes and + limit == p + SIZE + + "len" here could be from some externally supplied data (e.g. from a TLS + message). + + The rules of C pointer arithmetic are such that "p + len" is only well + defined where len <= SIZE. Therefore the above idiom is actually + undefined behaviour. + + For example this could cause problems if some malloc implementation + provides an address for "p" such that "p + len" actually overflows for + values of len that are too big and therefore p + len < limit. + + This issue was reported to OpenSSL by Guido Vranken + (CVE-2016-2177) + [Matt Caswell] + + *) Constant time flag not preserved in DSA signing + + Operations in the DSA signing algorithm should run in constant time in + order to avoid side channel attacks. A flaw in the OpenSSL DSA + implementation means that a non-constant time codepath is followed for + certain operations. This has been demonstrated through a cache-timing + attack to be sufficient for an attacker to recover the private DSA key. + + This issue was reported by César Pereida (Aalto University), Billy Brumley + (Tampere University of Technology), and Yuval Yarom (The University of + Adelaide and NICTA). + (CVE-2016-2178) + [César Pereida] + + *) DTLS buffered message DoS + + In a DTLS connection where handshake messages are delivered out-of-order + those messages that OpenSSL is not yet ready to process will be buffered + for later use. Under certain circumstances, a flaw in the logic means that + those messages do not get removed from the buffer even though the handshake + has been completed. An attacker could force up to approx. 15 messages to + remain in the buffer when they are no longer required. These messages will + be cleared when the DTLS connection is closed. The default maximum size for + a message is 100k. Therefore the attacker could force an additional 1500k + to be consumed per connection. By opening many simulataneous connections an + attacker could cause a DoS attack through memory exhaustion. + + This issue was reported to OpenSSL by Quan Luo. + (CVE-2016-2179) + [Matt Caswell] + + *) DTLS replay protection DoS + + A flaw in the DTLS replay attack protection mechanism means that records + that arrive for future epochs update the replay protection "window" before + the MAC for the record has been validated. This could be exploited by an + attacker by sending a record for the next epoch (which does not have to + decrypt or have a valid MAC), with a very large sequence number. This means + that all subsequent legitimate packets are dropped causing a denial of + service for a specific DTLS connection. + + This issue was reported to OpenSSL by the OCAP audit team. + (CVE-2016-2181) + [Matt Caswell] + + *) Certificate message OOB reads + + In OpenSSL 1.0.2 and earlier some missing message length checks can result + in OOB reads of up to 2 bytes beyond an allocated buffer. There is a + theoretical DoS risk but this has not been observed in practice on common + platforms. + + The messages affected are client certificate, client certificate request + and server certificate. As a result the attack can only be performed + against a client or a server which enables client authentication. + + This issue was reported to OpenSSL by Shi Lei (Gear Team, Qihoo 360 Inc.) + (CVE-2016-6306) + [Stephen Henson] + Changes between 1.0.2g and 1.0.2h [3 May 2016] *) Prevent padding oracle in AES-NI CBC MAC check Modified: releng/11.0/crypto/openssl/CONTRIBUTING ============================================================================== --- releng/11.0/crypto/openssl/CONTRIBUTING Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/CONTRIBUTING Thu Sep 22 15:55:27 2016 (r306198) @@ -1,38 +1,75 @@ -HOW TO CONTRIBUTE TO OpenSSL ----------------------------- +HOW TO CONTRIBUTE TO PATCHES OpenSSL +------------------------------------ -Development is coordinated on the openssl-dev mailing list (see -http://www.openssl.org for information on subscribing). If you -would like to submit a patch, send it to rt@openssl.org with -the string "[PATCH]" in the subject. Please be sure to include a -textual explanation of what your patch does. - -You can also make GitHub pull requests. If you do this, please also send -mail to rt@openssl.org with a brief description and a link to the PR so -that we can more easily keep track of it. +(Please visit https://www.openssl.org/community/getting-started.html for +other ideas about how to contribute.) +Development is coordinated on the openssl-dev mailing list (see the +above link or https://mta.openssl.org for information on subscribing). If you are unsure as to whether a feature will be useful for the general -OpenSSL community please discuss it on the openssl-dev mailing list first. -Someone may be already working on the same thing or there may be a good -reason as to why that feature isn't implemented. - -Patches should be as up to date as possible, preferably relative to the -current Git or the last snapshot. They should follow our coding style -(see https://www.openssl.org/policies/codingstyle.html) and compile without -warnings using the --strict-warnings flag. OpenSSL compiles on many varied -platforms: try to ensure you only use portable features. - -Our preferred format for patch files is "git format-patch" output. For example -to provide a patch file containing the last commit in your local git repository -use the following command: +OpenSSL community you might want to discuss it on the openssl-dev mailing +list first. Someone may be already working on the same thing or there +may be a good reason as to why that feature isn't implemented. + +The best way to submit a patch is to make a pull request on GitHub. +(It is not necessary to send mail to rt@openssl.org to open a ticket!) +If you think the patch could use feedback from the community, please +start a thread on openssl-dev. + +You can also submit patches by sending it as mail to rt@openssl.org. +Please include the word "PATCH" and an explanation of what the patch +does in the subject line. If you do this, our preferred format is "git +format-patch" output. For example to provide a patch file containing the +last commit in your local git repository use the following command: -# git format-patch --stdout HEAD^ >mydiffs.patch + % git format-patch --stdout HEAD^ >mydiffs.patch Another method of creating an acceptable patch file without using git is as follows: -# cd openssl-work -# [your changes] -# ./Configure dist; make clean -# cd .. -# diff -ur openssl-orig openssl-work > mydiffs.patch + % cd openssl-work + ...make your changes... + % ./Configure dist; make clean + % cd .. + % diff -ur openssl-orig openssl-work >mydiffs.patch + +Note that pull requests are generally easier for the team, and community, to +work with. Pull requests benefit from all of the standard GitHub features, +including code review tools, simpler integration, and CI build support. + +No matter how a patch is submitted, the following items will help make +the acceptance and review process faster: + + 1. Anything other than trivial contributions will require a contributor + licensing agreement, giving us permission to use your code. See + https://www.openssl.org/policies/cla.html for details. + + 2. All source files should start with the following text (with + appropriate comment characters at the start of each line and the + year(s) updated): + + Copyright 20xx-20yy The OpenSSL Project Authors. All Rights Reserved. + + Licensed under the OpenSSL license (the "License"). You may not use + this file except in compliance with the License. You can obtain a copy + in the file LICENSE in the source distribution or at + https://www.openssl.org/source/license.html + + 3. Patches should be as current as possible. When using GitHub, please + expect to have to rebase and update often. Note that we do not accept merge + commits. You will be asked to remove them before a patch is considered + acceptable. + + 4. Patches should follow our coding style (see + https://www.openssl.org/policies/codingstyle.html) and compile without + warnings. Where gcc or clang is availble you should use the + --strict-warnings Configure option. OpenSSL compiles on many varied + platforms: try to ensure you only use portable features. + + 5. When at all possible, patches should include tests. These can either be + added to an existing test, or completely new. Please see test/README + for information on the test framework. + + 6. New features or changed functionality must include documentation. Please + look at the "pod" files in doc/apps, doc/crypto and doc/ssl for examples of + our style. Modified: releng/11.0/crypto/openssl/Configure ============================================================================== --- releng/11.0/crypto/openssl/Configure Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/Configure Thu Sep 22 15:55:27 2016 (r306198) @@ -799,7 +799,7 @@ my @experimental = (); # This is what $depflags will look like with the above defaults # (we need this to see if we should advise the user to run "make depend"): -my $default_depflags = " -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_GMP -DOPENSSL_NO_JPAKE -DOPENSSL_NO_LIBUNBOUND -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST"; +my $default_depflags = " -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_GMP -DOPENSSL_NO_JPAKE -DOPENSSL_NO_LIBUNBOUND -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_SSL2 -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST -DOPENSSL_NO_WEAK_SSL_CIPHERS"; # Explicit "no-..." options will be collected in %disabled along with the defaults. # To remove something from %disabled, use "enable-foo" (unless it's experimental). @@ -1082,11 +1082,6 @@ if (defined($disabled{"md5"}) || defined $disabled{"tls1"} = "forced"; } -if (defined($disabled{"tls1"})) - { - $disabled{"tlsext"} = "forced"; - } - if (defined($disabled{"ec"}) || defined($disabled{"dsa"}) || defined($disabled{"dh"})) { @@ -1254,6 +1249,7 @@ my $shared_extension = $fields[$idx_shar my $ranlib = $ENV{'RANLIB'} || $fields[$idx_ranlib]; my $ar = $ENV{'AR'} || "ar"; my $arflags = $fields[$idx_arflags]; +my $windres = $ENV{'RC'} || $ENV{'WINDRES'} || "windres"; my $multilib = $fields[$idx_multilib]; # if $prefix/lib$multilib is not an existing directory, then @@ -1562,8 +1558,15 @@ $cpuid_obj="mem_clr.o" unless ($cpuid_ob $des_obj=$des_enc unless ($des_obj =~ /\.o$/); $bf_obj=$bf_enc unless ($bf_obj =~ /\.o$/); $cast_obj=$cast_enc unless ($cast_obj =~ /\.o$/); -$rc4_obj=$rc4_enc unless ($rc4_obj =~ /\.o$/); $rc5_obj=$rc5_enc unless ($rc5_obj =~ /\.o$/); +if ($rc4_obj =~ /\.o$/) + { + $cflags.=" -DRC4_ASM"; + } +else + { + $rc4_obj=$rc4_enc; + } if ($sha1_obj =~ /\.o$/) { # $sha1_obj=$sha1_enc; @@ -1717,12 +1720,14 @@ while () s/^AR=\s*/AR= \$\(CROSS_COMPILE\)/; s/^NM=\s*/NM= \$\(CROSS_COMPILE\)/; s/^RANLIB=\s*/RANLIB= \$\(CROSS_COMPILE\)/; + s/^RC=\s*/RC= \$\(CROSS_COMPILE\)/; s/^MAKEDEPPROG=.*$/MAKEDEPPROG= \$\(CROSS_COMPILE\)$cc/ if $cc eq "gcc"; } else { s/^CC=.*$/CC= $cc/; s/^AR=\s*ar/AR= $ar/; s/^RANLIB=.*/RANLIB= $ranlib/; + s/^RC=.*/RC= $windres/; s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc"; s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $ecc eq "gcc" || $ecc eq "clang"; } Modified: releng/11.0/crypto/openssl/Makefile ============================================================================== --- releng/11.0/crypto/openssl/Makefile Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/Makefile Thu Sep 22 15:55:27 2016 (r306198) @@ -4,7 +4,7 @@ ## Makefile for OpenSSL ## -VERSION=1.0.2h +VERSION=1.0.2i MAJOR=1 MINOR=0.2 SHLIB_VERSION_NUMBER=1.0.0 @@ -68,6 +68,7 @@ EXE_EXT= ARFLAGS= AR= ar $(ARFLAGS) r RANLIB= /usr/bin/ranlib +RC= windres NM= nm PERL= /usr/bin/perl TAR= tar @@ -210,6 +211,7 @@ BUILDENV= LC_ALL=C PLATFORM='$(PLATFORM) CC='$(CC)' CFLAG='$(CFLAG)' \ AS='$(CC)' ASFLAG='$(CFLAG) -c' \ AR='$(AR)' NM='$(NM)' RANLIB='$(RANLIB)' \ + RC='$(RC)' \ CROSS_COMPILE='$(CROSS_COMPILE)' \ PERL='$(PERL)' ENGDIRS='$(ENGDIRS)' \ SDIRS='$(SDIRS)' LIBRPATH='$(INSTALLTOP)/$(LIBDIR)' \ @@ -368,6 +370,7 @@ libcrypto.pc: Makefile echo 'exec_prefix=$${prefix}'; \ echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \ echo 'includedir=$${prefix}/include'; \ + echo 'enginesdir=$${libdir}/engines'; \ echo ''; \ echo 'Name: OpenSSL-libcrypto'; \ echo 'Description: OpenSSL cryptography library'; \ Modified: releng/11.0/crypto/openssl/Makefile.org ============================================================================== --- releng/11.0/crypto/openssl/Makefile.org Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/Makefile.org Thu Sep 22 15:55:27 2016 (r306198) @@ -66,6 +66,7 @@ EXE_EXT= ARFLAGS?= r AR=ar $(ARFLAGS) RANLIB= ranlib +RC= windres NM= nm PERL= perl TAR= tar @@ -208,6 +209,7 @@ BUILDENV= LC_ALL=C PLATFORM='$(PLATFORM) CC='$(CC)' CFLAG='$(CFLAG)' \ AS='$(CC)' ASFLAG='$(CFLAG) -c' \ AR='$(AR)' NM='$(NM)' RANLIB='$(RANLIB)' \ + RC='$(RC)' \ CROSS_COMPILE='$(CROSS_COMPILE)' \ PERL='$(PERL)' ENGDIRS='$(ENGDIRS)' \ SDIRS='$(SDIRS)' LIBRPATH='$(INSTALLTOP)/$(LIBDIR)' \ @@ -366,6 +368,7 @@ libcrypto.pc: Makefile echo 'exec_prefix=$${prefix}'; \ echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \ echo 'includedir=$${prefix}/include'; \ + echo 'enginesdir=$${libdir}/engines'; \ echo ''; \ echo 'Name: OpenSSL-libcrypto'; \ echo 'Description: OpenSSL cryptography library'; \ Modified: releng/11.0/crypto/openssl/Makefile.shared ============================================================================== --- releng/11.0/crypto/openssl/Makefile.shared Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/Makefile.shared Thu Sep 22 15:55:27 2016 (r306198) @@ -293,7 +293,7 @@ link_a.cygwin: fi; \ dll_name=$$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX; \ $(PERL) util/mkrc.pl $$dll_name | \ - $(CROSS_COMPILE)windres -o rc.o; \ + $(RC) -o rc.o; \ extras="$$extras rc.o"; \ ALLSYMSFLAGS='-Wl,--whole-archive'; \ NOALLSYMSFLAGS='-Wl,--no-whole-archive'; \ Modified: releng/11.0/crypto/openssl/NEWS ============================================================================== --- releng/11.0/crypto/openssl/NEWS Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/NEWS Thu Sep 22 15:55:27 2016 (r306198) @@ -5,6 +5,20 @@ This file gives a brief overview of the major changes between each OpenSSL release. For more details please read the CHANGES file. + Major changes between OpenSSL 1.0.2h and OpenSSL 1.0.2i [22 Sep 2016] + + o OCSP Status Request extension unbounded memory growth (CVE-2016-6304) + o SWEET32 Mitigation (CVE-2016-2183) + o OOB write in MDC2_Update() (CVE-2016-6303) + o Malformed SHA512 ticket DoS (CVE-2016-6302) + o OOB write in BN_bn2dec() (CVE-2016-2182) + o OOB read in TS_OBJ_print_bio() (CVE-2016-2180) + o Pointer arithmetic undefined behaviour (CVE-2016-2177) + o Constant time flag not preserved in DSA signing (CVE-2016-2178) + o DTLS buffered message DoS (CVE-2016-2179) + o DTLS replay protection DoS (CVE-2016-2181) + o Certificate message OOB reads (CVE-2016-6306) + Major changes between OpenSSL 1.0.2g and OpenSSL 1.0.2h [3 May 2016] o Prevent padding oracle in AES-NI CBC MAC check (CVE-2016-2107) Modified: releng/11.0/crypto/openssl/README ============================================================================== --- releng/11.0/crypto/openssl/README Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/README Thu Sep 22 15:55:27 2016 (r306198) @@ -1,5 +1,5 @@ - OpenSSL 1.0.2h 3 May 2016 + OpenSSL 1.0.2i 22 Sep 2016 Copyright (c) 1998-2015 The OpenSSL Project Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson Modified: releng/11.0/crypto/openssl/apps/CA.pl ============================================================================== --- releng/11.0/crypto/openssl/apps/CA.pl Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/CA.pl Thu Sep 22 15:55:27 2016 (r306198) @@ -64,7 +64,7 @@ $RET = 0; foreach (@ARGV) { if ( /^(-\?|-h|-help)$/ ) { - print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-verify\n"; + print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-signcert|-verify\n"; exit 0; } elsif (/^-newcert$/) { # create a certificate @@ -186,4 +186,3 @@ while () { } } } - Modified: releng/11.0/crypto/openssl/apps/CA.pl.in ============================================================================== --- releng/11.0/crypto/openssl/apps/CA.pl.in Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/CA.pl.in Thu Sep 22 15:55:27 2016 (r306198) @@ -64,7 +64,7 @@ $RET = 0; foreach (@ARGV) { if ( /^(-\?|-h|-help)$/ ) { - print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-verify\n"; + print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-signcert|-verify\n"; exit 0; } elsif (/^-newcert$/) { # create a certificate @@ -186,4 +186,3 @@ while () { } } } - Modified: releng/11.0/crypto/openssl/apps/apps.c ============================================================================== --- releng/11.0/crypto/openssl/apps/apps.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/apps.c Thu Sep 22 15:55:27 2016 (r306198) @@ -215,7 +215,8 @@ int args_from_file(char *file, int *argc if (arg != NULL) OPENSSL_free(arg); arg = (char **)OPENSSL_malloc(sizeof(char *) * (i * 2)); - + if (arg == NULL) + return 0; *argv = arg; num = 0; p = buf; @@ -2374,6 +2375,8 @@ int args_verify(char ***pargs, int *parg flags |= X509_V_FLAG_PARTIAL_CHAIN; else if (!strcmp(arg, "-no_alt_chains")) flags |= X509_V_FLAG_NO_ALT_CHAINS; + else if (!strcmp(arg, "-allow_proxy_certs")) + flags |= X509_V_FLAG_ALLOW_PROXY_CERTS; else return 0; @@ -3195,6 +3198,36 @@ int app_isdir(const char *name) #endif /* raw_read|write section */ +#if defined(__VMS) +# include "vms_term_sock.h" +static int stdin_sock = -1; + +static void close_stdin_sock(void) +{ + TerminalSocket (TERM_SOCK_DELETE, &stdin_sock); +} + +int fileno_stdin(void) +{ + if (stdin_sock == -1) { + TerminalSocket(TERM_SOCK_CREATE, &stdin_sock); + atexit(close_stdin_sock); + } + + return stdin_sock; +} +#else +int fileno_stdin(void) +{ + return fileno(stdin); +} +#endif + +int fileno_stdout(void) +{ + return fileno(stdout); +} + #if defined(_WIN32) && defined(STD_INPUT_HANDLE) int raw_read_stdin(void *buf, int siz) { @@ -3204,10 +3237,17 @@ int raw_read_stdin(void *buf, int siz) else return (-1); } +#elif defined(__VMS) +#include + +int raw_read_stdin(void *buf, int siz) +{ + return recv(fileno_stdin(), buf, siz, 0); +} #else int raw_read_stdin(void *buf, int siz) { - return read(fileno(stdin), buf, siz); + return read(fileno_stdin(), buf, siz); } #endif @@ -3223,6 +3263,6 @@ int raw_write_stdout(const void *buf, in #else int raw_write_stdout(const void *buf, int siz) { - return write(fileno(stdout), buf, siz); + return write(fileno_stdout(), buf, siz); } #endif Modified: releng/11.0/crypto/openssl/apps/apps.h ============================================================================== --- releng/11.0/crypto/openssl/apps/apps.h Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/apps.h Thu Sep 22 15:55:27 2016 (r306198) @@ -375,6 +375,8 @@ void store_setup_crl_download(X509_STORE # define SERIAL_RAND_BITS 64 int app_isdir(const char *); +int fileno_stdin(void); +int fileno_stdout(void); int raw_read_stdin(void *, int); int raw_write_stdout(const void *, int); Modified: releng/11.0/crypto/openssl/apps/ca.c ============================================================================== --- releng/11.0/crypto/openssl/apps/ca.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/ca.c Thu Sep 22 15:55:27 2016 (r306198) @@ -2103,25 +2103,23 @@ static int do_body(X509 **xret, EVP_PKEY goto err; /* We now just add it to the database */ - row[DB_type] = (char *)OPENSSL_malloc(2); - tm = X509_get_notAfter(ret); - row[DB_exp_date] = (char *)OPENSSL_malloc(tm->length + 1); - memcpy(row[DB_exp_date], tm->data, tm->length); - row[DB_exp_date][tm->length] = '\0'; - - row[DB_rev_date] = NULL; - - /* row[DB_serial] done already */ - row[DB_file] = (char *)OPENSSL_malloc(8); + row[DB_type] = OPENSSL_malloc(2); + row[DB_exp_date] = OPENSSL_malloc(tm->length + 1); + row[DB_rev_date] = OPENSSL_malloc(1); + row[DB_file] = OPENSSL_malloc(8); row[DB_name] = X509_NAME_oneline(X509_get_subject_name(ret), NULL, 0); - if ((row[DB_type] == NULL) || (row[DB_exp_date] == NULL) || + (row[DB_rev_date] == NULL) || (row[DB_file] == NULL) || (row[DB_name] == NULL)) { BIO_printf(bio_err, "Memory allocation failure\n"); goto err; } - BUF_strlcpy(row[DB_file], "unknown", 8); + + memcpy(row[DB_exp_date], tm->data, tm->length); + row[DB_exp_date][tm->length] = '\0'; + row[DB_rev_date][0] = '\0'; + strcpy(row[DB_file], "unknown"); row[DB_type][0] = 'V'; row[DB_type][1] = '\0'; @@ -2307,6 +2305,7 @@ static int certify_spkac(X509 **xret, ch j = NETSCAPE_SPKI_verify(spki, pktmp); if (j <= 0) { + EVP_PKEY_free(pktmp); BIO_printf(bio_err, "signature verification failed on SPKAC public key\n"); goto err; Modified: releng/11.0/crypto/openssl/apps/dgst.c ============================================================================== --- releng/11.0/crypto/openssl/apps/dgst.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/dgst.c Thu Sep 22 15:55:27 2016 (r306198) @@ -243,6 +243,11 @@ int MAIN(int argc, char **argv) argv++; } + if (keyfile != NULL && argc > 1) { + BIO_printf(bio_err, "Can only sign or verify one file\n"); + goto end; + } + if (do_verify && !sigfile) { BIO_printf(bio_err, "No signature to verify: use the -signature option\n"); Modified: releng/11.0/crypto/openssl/apps/enc.c ============================================================================== --- releng/11.0/crypto/openssl/apps/enc.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/enc.c Thu Sep 22 15:55:27 2016 (r306198) @@ -509,7 +509,7 @@ int MAIN(int argc, char **argv) BIO_printf(bio_err, "invalid hex salt value\n"); goto end; } - } else if (RAND_pseudo_bytes(salt, sizeof salt) < 0) + } else if (RAND_bytes(salt, sizeof salt) <= 0) goto end; /* * If -P option then don't bother writing Modified: releng/11.0/crypto/openssl/apps/passwd.c ============================================================================== --- releng/11.0/crypto/openssl/apps/passwd.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/passwd.c Thu Sep 22 15:55:27 2016 (r306198) @@ -416,7 +416,7 @@ static int do_passwd(int passed_salt, ch if (*salt_malloc_p == NULL) goto err; } - if (RAND_pseudo_bytes((unsigned char *)*salt_p, 2) < 0) + if (RAND_bytes((unsigned char *)*salt_p, 2) <= 0) goto err; (*salt_p)[0] = cov_2char[(*salt_p)[0] & 0x3f]; /* 6 bits */ (*salt_p)[1] = cov_2char[(*salt_p)[1] & 0x3f]; /* 6 bits */ @@ -437,7 +437,7 @@ static int do_passwd(int passed_salt, ch if (*salt_malloc_p == NULL) goto err; } - if (RAND_pseudo_bytes((unsigned char *)*salt_p, 8) < 0) + if (RAND_bytes((unsigned char *)*salt_p, 8) <= 0) goto err; for (i = 0; i < 8; i++) Modified: releng/11.0/crypto/openssl/apps/pkcs12.c ============================================================================== --- releng/11.0/crypto/openssl/apps/pkcs12.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/pkcs12.c Thu Sep 22 15:55:27 2016 (r306198) @@ -832,6 +832,7 @@ int dump_certs_pkeys_bag(BIO *out, PKCS1 EVP_PKEY *pkey; PKCS8_PRIV_KEY_INFO *p8; X509 *x509; + int ret = 0; switch (M_PKCS12_bag_type(bag)) { case NID_keyBag: @@ -844,7 +845,7 @@ int dump_certs_pkeys_bag(BIO *out, PKCS1 if (!(pkey = EVP_PKCS82PKEY(p8))) return 0; print_attribs(out, p8->attributes, "Key Attributes"); - PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, pempass); + ret = PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, pempass); EVP_PKEY_free(pkey); break; @@ -864,7 +865,7 @@ int dump_certs_pkeys_bag(BIO *out, PKCS1 } print_attribs(out, p8->attributes, "Key Attributes"); PKCS8_PRIV_KEY_INFO_free(p8); - PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, pempass); + ret = PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, pempass); EVP_PKEY_free(pkey); break; @@ -884,7 +885,7 @@ int dump_certs_pkeys_bag(BIO *out, PKCS1 if (!(x509 = PKCS12_certbag2x509(bag))) return 0; dump_cert_text(out, x509); - PEM_write_bio_X509(out, x509); + ret = PEM_write_bio_X509(out, x509); X509_free(x509); break; @@ -902,7 +903,7 @@ int dump_certs_pkeys_bag(BIO *out, PKCS1 return 1; break; } - return 1; + return ret; } /* Given a single certificate return a verified chain or NULL if error */ @@ -931,16 +932,70 @@ static int get_cert_chain(X509 *cert, X5 int alg_print(BIO *x, X509_ALGOR *alg) { - PBEPARAM *pbe; - const unsigned char *p; - p = alg->parameter->value.sequence->data; - pbe = d2i_PBEPARAM(NULL, &p, alg->parameter->value.sequence->length); - if (!pbe) - return 1; - BIO_printf(bio_err, "%s, Iteration %ld\n", - OBJ_nid2ln(OBJ_obj2nid(alg->algorithm)), - ASN1_INTEGER_get(pbe->iter)); - PBEPARAM_free(pbe); + int pbenid, aparamtype; + ASN1_OBJECT *aoid; + void *aparam; + PBEPARAM *pbe = NULL; + + X509_ALGOR_get0(&aoid, &aparamtype, &aparam, alg); + + pbenid = OBJ_obj2nid(aoid); + + BIO_printf(x, "%s", OBJ_nid2ln(pbenid)); + + /* + * If PBE algorithm is PBES2 decode algorithm parameters + * for additional details. + */ + if (pbenid == NID_pbes2) { + PBE2PARAM *pbe2 = NULL; + int encnid; + if (aparamtype == V_ASN1_SEQUENCE) + pbe2 = ASN1_item_unpack(aparam, ASN1_ITEM_rptr(PBE2PARAM)); + if (pbe2 == NULL) { + BIO_puts(x, ""); + goto done; + } + X509_ALGOR_get0(&aoid, &aparamtype, &aparam, pbe2->keyfunc); + pbenid = OBJ_obj2nid(aoid); + X509_ALGOR_get0(&aoid, NULL, NULL, pbe2->encryption); + encnid = OBJ_obj2nid(aoid); + BIO_printf(x, ", %s, %s", OBJ_nid2ln(pbenid), + OBJ_nid2sn(encnid)); + /* If KDF is PBKDF2 decode parameters */ + if (pbenid == NID_id_pbkdf2) { + PBKDF2PARAM *kdf = NULL; + int prfnid; + if (aparamtype == V_ASN1_SEQUENCE) + kdf = ASN1_item_unpack(aparam, ASN1_ITEM_rptr(PBKDF2PARAM)); + if (kdf == NULL) { + BIO_puts(x, ""); + goto done; + } + + if (kdf->prf == NULL) { + prfnid = NID_hmacWithSHA1; + } else { + X509_ALGOR_get0(&aoid, NULL, NULL, kdf->prf); + prfnid = OBJ_obj2nid(aoid); + } + BIO_printf(x, ", Iteration %ld, PRF %s", + ASN1_INTEGER_get(kdf->iter), OBJ_nid2sn(prfnid)); + PBKDF2PARAM_free(kdf); + } + PBE2PARAM_free(pbe2); + } else { + if (aparamtype == V_ASN1_SEQUENCE) + pbe = ASN1_item_unpack(aparam, ASN1_ITEM_rptr(PBEPARAM)); + if (pbe == NULL) { + BIO_puts(x, ""); + goto done; + } + BIO_printf(x, ", Iteration %ld", ASN1_INTEGER_get(pbe->iter)); + PBEPARAM_free(pbe); + } + done: + BIO_puts(x, "\n"); return 1; } Modified: releng/11.0/crypto/openssl/apps/req.c ============================================================================== --- releng/11.0/crypto/openssl/apps/req.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/req.c Thu Sep 22 15:55:27 2016 (r306198) @@ -332,9 +332,10 @@ int MAIN(int argc, char **argv) subject = 1; else if (strcmp(*argv, "-text") == 0) text = 1; - else if (strcmp(*argv, "-x509") == 0) + else if (strcmp(*argv, "-x509") == 0) { + newreq = 1; x509 = 1; - else if (strcmp(*argv, "-asn1-kludge") == 0) + } else if (strcmp(*argv, "-asn1-kludge") == 0) kludge = 1; else if (strcmp(*argv, "-no-asn1-kludge") == 0) kludge = 0; @@ -756,7 +757,7 @@ int MAIN(int argc, char **argv) } } - if (newreq || x509) { + if (newreq) { if (pkey == NULL) { BIO_printf(bio_err, "you need to specify a private key\n"); goto end; @@ -1331,12 +1332,11 @@ static int auto_info(X509_REQ *req, STAC break; } #ifndef CHARSET_EBCDIC - if (*p == '+') + if (*type == '+') { #else - if (*p == os_toascii['+']) + if (*type == os_toascii['+']) { #endif - { - p++; + type++; mval = -1; } else mval = 0; Modified: releng/11.0/crypto/openssl/apps/s_apps.h ============================================================================== --- releng/11.0/crypto/openssl/apps/s_apps.h Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/s_apps.h Thu Sep 22 15:55:27 2016 (r306198) @@ -199,7 +199,8 @@ int load_excert(SSL_EXCERT **pexc, BIO * void print_ssl_summary(BIO *bio, SSL *s); #ifdef HEADER_SSL_H int args_ssl(char ***pargs, int *pargc, SSL_CONF_CTX *cctx, - int *badarg, BIO *err, STACK_OF(OPENSSL_STRING) **pstr); + int *badarg, BIO *err, STACK_OF(OPENSSL_STRING) **pstr, + int *no_prot_opt); int args_ssl_call(SSL_CTX *ctx, BIO *err, SSL_CONF_CTX *cctx, STACK_OF(OPENSSL_STRING) *str, int no_ecdhe, int no_jpake); int ssl_ctx_add_crls(SSL_CTX *ctx, STACK_OF(X509_CRL) *crls, Modified: releng/11.0/crypto/openssl/apps/s_cb.c ============================================================================== --- releng/11.0/crypto/openssl/apps/s_cb.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/s_cb.c Thu Sep 22 15:55:27 2016 (r306198) @@ -1507,11 +1507,18 @@ void print_ssl_summary(BIO *bio, SSL *s) } int args_ssl(char ***pargs, int *pargc, SSL_CONF_CTX *cctx, - int *badarg, BIO *err, STACK_OF(OPENSSL_STRING) **pstr) + int *badarg, BIO *err, STACK_OF(OPENSSL_STRING) **pstr, + int *no_prot_opt) { char *arg = **pargs, *argn = (*pargs)[1]; int rv; + if (strcmp(arg, "-no_ssl2") == 0 || strcmp(arg, "-no_ssl3") == 0 + || strcmp(arg, "-no_tls1") == 0 || strcmp(arg, "-no_tls1_1") == 0 + || strcmp(arg, "-no_tls1_2") == 0) { + *no_prot_opt = 1; + } + /* Attempt to run SSL configuration command */ rv = SSL_CONF_cmd_argv(cctx, pargc, pargs); /* If parameter not recognised just return */ Modified: releng/11.0/crypto/openssl/apps/s_client.c ============================================================================== --- releng/11.0/crypto/openssl/apps/s_client.c Thu Sep 22 15:17:36 2016 (r306197) +++ releng/11.0/crypto/openssl/apps/s_client.c Thu Sep 22 15:55:27 2016 (r306198) @@ -242,9 +242,9 @@ static unsigned int psk_client_cb(SSL *s unsigned char *psk, unsigned int max_psk_len) { - unsigned int psk_len = 0; int ret; - BIGNUM *bn = NULL; + long key_len; + unsigned char *key; if (c_debug) BIO_printf(bio_c_out, "psk_client_cb\n"); @@ -265,32 +265,29 @@ static unsigned int psk_client_cb(SSL *s if (c_debug) BIO_printf(bio_c_out, "created identity '%s' len=%d\n", identity, ret); - ret = BN_hex2bn(&bn, psk_key); - if (!ret) { - BIO_printf(bio_err, "Could not convert PSK key '%s' to BIGNUM\n", + + /* convert the PSK key to binary */ + key = string_to_hex(psk_key, &key_len); + if (key == NULL) { + BIO_printf(bio_err, "Could not convert PSK key '%s' to buffer\n", psk_key); - if (bn) - BN_free(bn); return 0; } - - if ((unsigned int)BN_num_bytes(bn) > max_psk_len) { + if ((unsigned long)key_len > (unsigned long)max_psk_len) { BIO_printf(bio_err, - "psk buffer of callback is too small (%d) for key (%d)\n", - max_psk_len, BN_num_bytes(bn)); - BN_free(bn); + "psk buffer of callback is too small (%d) for key (%ld)\n", + max_psk_len, key_len); + OPENSSL_free(key); return 0; } - psk_len = BN_bn2bin(bn, psk); - BN_free(bn); - if (psk_len == 0) - goto out_err; + memcpy(psk, key, key_len); + OPENSSL_free(key); if (c_debug) - BIO_printf(bio_c_out, "created PSK len=%d\n", psk_len); + BIO_printf(bio_c_out, "created PSK len=%ld\n", key_len); - return psk_len; + return key_len; out_err: if (c_debug) BIO_printf(bio_err, "Error in PSK client callback\n"); @@ -747,6 +744,7 @@ int MAIN(int argc, char **argv) int crl_format = FORMAT_PEM; int crl_download = 0; STACK_OF(X509_CRL) *crls = NULL; + int prot_opt = 0, no_prot_opt = 0; meth = SSLv23_client_method(); @@ -850,7 +848,8 @@ int MAIN(int argc, char **argv) if (badarg) goto bad; continue; - } else if (args_ssl(&argv, &argc, cctx, &badarg, bio_err, &ssl_args)) { + } else if (args_ssl(&argv, &argc, cctx, &badarg, bio_err, &ssl_args, + &no_prot_opt)) { if (badarg) goto bad; continue; @@ -942,31 +941,42 @@ int MAIN(int argc, char **argv) } #endif #ifndef OPENSSL_NO_SSL2 - else if (strcmp(*argv, "-ssl2") == 0) + else if (strcmp(*argv, "-ssl2") == 0) { meth = SSLv2_client_method(); + prot_opt++; + } #endif #ifndef OPENSSL_NO_SSL3_METHOD - else if (strcmp(*argv, "-ssl3") == 0) + else if (strcmp(*argv, "-ssl3") == 0) { meth = SSLv3_client_method(); + prot_opt++; + } #endif #ifndef OPENSSL_NO_TLS1 - else if (strcmp(*argv, "-tls1_2") == 0) + else if (strcmp(*argv, "-tls1_2") == 0) { meth = TLSv1_2_client_method(); - else if (strcmp(*argv, "-tls1_1") == 0) + prot_opt++; + } else if (strcmp(*argv, "-tls1_1") == 0) { meth = TLSv1_1_client_method(); - else if (strcmp(*argv, "-tls1") == 0) + prot_opt++; + } else if (strcmp(*argv, "-tls1") == 0) { meth = TLSv1_client_method(); + prot_opt++; + } #endif #ifndef OPENSSL_NO_DTLS1 else if (strcmp(*argv, "-dtls") == 0) { meth = DTLS_client_method(); socket_type = SOCK_DGRAM; + prot_opt++; } else if (strcmp(*argv, "-dtls1") == 0) { meth = DTLSv1_client_method(); socket_type = SOCK_DGRAM; + prot_opt++; } else if (strcmp(*argv, "-dtls1_2") == 0) { meth = DTLSv1_2_client_method(); socket_type = SOCK_DGRAM; + prot_opt++; } else if (strcmp(*argv, "-timeout") == 0) enable_timeouts = 1; else if (strcmp(*argv, "-mtu") == 0) { @@ -1149,6 +1159,17 @@ int MAIN(int argc, char **argv) } #endif + if (prot_opt > 1) { + BIO_printf(bio_err, "Cannot supply multiple protocol flags\n"); + goto end; + } + + if (prot_opt == 1 && no_prot_opt) { *** DIFF OUTPUT TRUNCATED AT 1000 LINES *** From owner-svn-src-releng@freebsd.org Thu Sep 22 18:13:00 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id A1116BE6725; Thu, 22 Sep 2016 18:13:00 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 712FAF8F; Thu, 22 Sep 2016 18:13:00 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MICxxI029571; Thu, 22 Sep 2016 18:12:59 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MICxXW029570; Thu, 22 Sep 2016 18:12:59 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221812.u8MICxXW029570@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 18:12:59 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306202 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 18:13:00 -0000 Author: gjb Date: Thu Sep 22 18:12:59 2016 New Revision: 306202 URL: https://svnweb.freebsd.org/changeset/base/306202 Log: Document r306198, OpenSSL 1.0.2i. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 16:49:53 2016 (r306201) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 18:12:59 2016 (r306202) @@ -619,9 +619,6 @@ The &man.svnlite.1; utility has been updated to version 1.9.4. - OpenSSL has - been updated to version 1.0.2h. - ACPICA has been updated to version 20160527. @@ -661,6 +658,9 @@ Support for DSA is disabled by default in OpenSSH. + + OpenSSL has + been updated to version 1.0.2i. From owner-svn-src-releng@freebsd.org Thu Sep 22 18:19:13 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 60C35BE6B8B; Thu, 22 Sep 2016 18:19:13 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 302FE31C; Thu, 22 Sep 2016 18:19:13 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MIJCLJ029807; Thu, 22 Sep 2016 18:19:12 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MIJC0q029806; Thu, 22 Sep 2016 18:19:12 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221819.u8MIJC0q029806@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 18:19:12 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306203 - releng/11.0/release/doc/share/xml X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 18:19:13 -0000 Author: gjb Date: Thu Sep 22 18:19:12 2016 New Revision: 306203 URL: https://svnweb.freebsd.org/changeset/base/306203 Log: Change the entity for arm64 from 'aarch64' to 'arm64'. Submitted by: emaste Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/share/xml/release.ent Modified: releng/11.0/release/doc/share/xml/release.ent ============================================================================== --- releng/11.0/release/doc/share/xml/release.ent Thu Sep 22 18:12:59 2016 (r306202) +++ releng/11.0/release/doc/share/xml/release.ent Thu Sep 22 18:19:12 2016 (r306203) @@ -70,7 +70,7 @@ - + From owner-svn-src-releng@freebsd.org Thu Sep 22 18:31:51 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 34545BE6F7E; Thu, 22 Sep 2016 18:31:51 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 071D5D5F; Thu, 22 Sep 2016 18:31:50 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MIVoxi033792; Thu, 22 Sep 2016 18:31:50 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MIVojC033791; Thu, 22 Sep 2016 18:31:50 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221831.u8MIVojC033791@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 18:31:50 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306204 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 18:31:51 -0000 Author: gjb Date: Thu Sep 22 18:31:50 2016 New Revision: 306204 URL: https://svnweb.freebsd.org/changeset/base/306204 Log: Add a link to the 'installation.html' section for freebsd-update(8) usage information. Suggested by: theraven Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 18:19:12 2016 (r306203) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 18:31:50 2016 (r306204) @@ -9,6 +9,7 @@ %vendor; + ]>
@@ -144,6 +145,11 @@ supported, using the instructions in /usr/src/UPDATING. + For information on upgrading via &man.freebsd-update.8;, + please see the binary + upgrading section in the Installation page. + Upgrading &os; should only be attempted after backing up all data and configuration files. From owner-svn-src-releng@freebsd.org Thu Sep 22 18:51:38 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id A79B5BE5814; Thu, 22 Sep 2016 18:51:38 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 58DF4D61; Thu, 22 Sep 2016 18:51:38 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MIpbjw041518; Thu, 22 Sep 2016 18:51:37 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MIpbXw041517; Thu, 22 Sep 2016 18:51:37 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221851.u8MIpbXw041517@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 18:51:37 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306207 - releng/11.0/release/doc/en_US.ISO8859-1/relnotes X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 18:51:38 -0000 Author: gjb Date: Thu Sep 22 18:51:37 2016 New Revision: 306207 URL: https://svnweb.freebsd.org/changeset/base/306207 Log: Remove dual-revision entries, and prefer the latter, unbreaking URLs to svnweb. Submitted by: jkim Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Modified: releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml ============================================================================== --- releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 18:47:07 2016 (r306206) +++ releng/11.0/release/doc/en_US.ISO8859-1/relnotes/article.xml Thu Sep 22 18:51:37 2016 (r306207) @@ -799,11 +799,10 @@ features %U and %W. - The &man.dl.iterate.phdr.3; library has been - changed to always return the path name of the - ELF object in the - dlpi_name structure member. + The + &man.dl.iterate.phdr.3; library has been changed to always + return the path name of the ELF object in + the dlpi_name structure member. The &man.libxo.3; library has been @@ -1124,10 +1123,10 @@ and kern.osreldate are now configurable &man.jail.8; parameters. - The &man.devfs.5; device filesystem has - been changed to update timestamps for read/write operations - using seconds precision. A new &man.sysctl.8;, + The &man.devfs.5; device filesystem has been changed to + update timestamps for read/write operations using seconds + precision. A new &man.sysctl.8;, vfs.devfs.dotimes has been added, which when set to a non-zero value, enables default precision timestamps for these operations. @@ -1411,7 +1410,7 @@ certain PowerPC hardware, such as aluminum PowerBook ®. - The &man.hwpmc.4; driver has been + The &man.hwpmc.4; driver has been updated to correct performance counter sampling on PowerPC G4 (MPC74xxx) and G5 class processors. From owner-svn-src-releng@freebsd.org Thu Sep 22 19:04:09 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B5694BE5AB5; Thu, 22 Sep 2016 19:04:09 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 87D1976D; Thu, 22 Sep 2016 19:04:09 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MJ48oq048605; Thu, 22 Sep 2016 19:04:08 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MJ48kL048604; Thu, 22 Sep 2016 19:04:08 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221904.u8MJ48kL048604@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 19:04:08 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306208 - releng/11.0/lib/csu/common X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 19:04:09 -0000 Author: gjb Date: Thu Sep 22 19:04:08 2016 New Revision: 306208 URL: https://svnweb.freebsd.org/changeset/base/306208 Log: Statically set __FreeBSD_version for 11.0-RELEASE. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/lib/csu/common/crtbrand.c Modified: releng/11.0/lib/csu/common/crtbrand.c ============================================================================== --- releng/11.0/lib/csu/common/crtbrand.c Thu Sep 22 18:51:37 2016 (r306207) +++ releng/11.0/lib/csu/common/crtbrand.c Thu Sep 22 19:04:08 2016 (r306208) @@ -62,5 +62,5 @@ static const struct { .descsz = sizeof(int32_t), .type = ABI_NOTETYPE, .name = NOTE_FREEBSD_VENDOR, - .desc = __FreeBSD_version + .desc = 1100122 }; From owner-svn-src-releng@freebsd.org Thu Sep 22 19:05:42 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 914EDBE5B74; Thu, 22 Sep 2016 19:05:42 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 61C9CA6A; Thu, 22 Sep 2016 19:05:42 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MJ5fXt048750; Thu, 22 Sep 2016 19:05:41 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MJ5fVc048749; Thu, 22 Sep 2016 19:05:41 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221905.u8MJ5fVc048749@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 19:05:41 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306210 - releng/11.0 X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 19:05:42 -0000 Author: gjb Date: Thu Sep 22 19:05:41 2016 New Revision: 306210 URL: https://svnweb.freebsd.org/changeset/base/306210 Log: Anticipate when we will be ready to announce 11.0-RELEASE. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/UPDATING Modified: releng/11.0/UPDATING ============================================================================== --- releng/11.0/UPDATING Thu Sep 22 19:04:51 2016 (r306209) +++ releng/11.0/UPDATING Thu Sep 22 19:05:41 2016 (r306210) @@ -16,6 +16,9 @@ from older versions of FreeBSD, try WITH the tip of head, and then rebuild without this option. The bootstrap process from older version of current across the gcc/clang cutover is a bit fragile. +20160928: + 11.0-RELEASE. + 20160622: The libc stub for the pipe(2) system call has been replaced with a wrapper that calls the pipe2(2) system call and the pipe(2) From owner-svn-src-releng@freebsd.org Thu Sep 22 19:16:09 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 42587BE5185; Thu, 22 Sep 2016 19:16:09 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 1588EFE; Thu, 22 Sep 2016 19:16:09 +0000 (UTC) (envelope-from gjb@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8MJG8BX052434; Thu, 22 Sep 2016 19:16:08 GMT (envelope-from gjb@FreeBSD.org) Received: (from gjb@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8MJG80E052433; Thu, 22 Sep 2016 19:16:08 GMT (envelope-from gjb@FreeBSD.org) Message-Id: <201609221916.u8MJG80E052433@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: gjb set sender to gjb@FreeBSD.org using -f From: Glen Barber Date: Thu, 22 Sep 2016 19:16:08 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306211 - releng/11.0/sys/conf X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2016 19:16:09 -0000 Author: gjb Date: Thu Sep 22 19:16:08 2016 New Revision: 306211 URL: https://svnweb.freebsd.org/changeset/base/306211 Log: Prepare for 11.0-RELEASE builds. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Modified: releng/11.0/sys/conf/newvers.sh Modified: releng/11.0/sys/conf/newvers.sh ============================================================================== --- releng/11.0/sys/conf/newvers.sh Thu Sep 22 19:05:41 2016 (r306210) +++ releng/11.0/sys/conf/newvers.sh Thu Sep 22 19:16:08 2016 (r306211) @@ -32,7 +32,7 @@ TYPE="FreeBSD" REVISION="11.0" -BRANCH="RC3" +BRANCH="RELEASE" if [ -n "${BRANCH_OVERRIDE}" ]; then BRANCH=${BRANCH_OVERRIDE} fi From owner-svn-src-releng@freebsd.org Fri Sep 23 07:48:38 2016 Return-Path: Delivered-To: svn-src-releng@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id ECB01BE51B6; Fri, 23 Sep 2016 07:48:37 +0000 (UTC) (envelope-from delphij@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 857961EEA; Fri, 23 Sep 2016 07:48:37 +0000 (UTC) (envelope-from delphij@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u8N7makI034790; Fri, 23 Sep 2016 07:48:36 GMT (envelope-from delphij@FreeBSD.org) Received: (from delphij@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u8N7mYqe034765; Fri, 23 Sep 2016 07:48:34 GMT (envelope-from delphij@FreeBSD.org) Message-Id: <201609230748.u8N7mYqe034765@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: delphij set sender to delphij@FreeBSD.org using -f From: Xin LI Date: Fri, 23 Sep 2016 07:48:34 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-releng@freebsd.org Subject: svn commit: r306230 - in releng: 10.1 10.1/crypto/openssl/crypto/bn 10.1/crypto/openssl/crypto/dsa 10.1/crypto/openssl/crypto/mdc2 10.1/crypto/openssl/crypto/ts 10.1/crypto/openssl/ssl 10.1/sys/con... X-SVN-Group: releng MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-releng@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the release engineering / security commits to the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Sep 2016 07:48:38 -0000 Author: delphij Date: Fri Sep 23 07:48:34 2016 New Revision: 306230 URL: https://svnweb.freebsd.org/changeset/base/306230 Log: Fix multiple OpenSSL vulnerabilitites. Approved by: so Security: FreeBSD-SA-16:26.openssl Modified: releng/10.1/UPDATING releng/10.1/crypto/openssl/crypto/bn/bn_print.c releng/10.1/crypto/openssl/crypto/dsa/dsa_ossl.c releng/10.1/crypto/openssl/crypto/mdc2/mdc2dgst.c releng/10.1/crypto/openssl/crypto/ts/ts_lib.c releng/10.1/crypto/openssl/ssl/d1_both.c releng/10.1/crypto/openssl/ssl/d1_clnt.c releng/10.1/crypto/openssl/ssl/d1_lib.c releng/10.1/crypto/openssl/ssl/d1_pkt.c releng/10.1/crypto/openssl/ssl/d1_srvr.c releng/10.1/crypto/openssl/ssl/s3_clnt.c releng/10.1/crypto/openssl/ssl/s3_srvr.c releng/10.1/crypto/openssl/ssl/ssl.h releng/10.1/crypto/openssl/ssl/ssl_err.c releng/10.1/crypto/openssl/ssl/ssl_locl.h releng/10.1/crypto/openssl/ssl/ssl_sess.c releng/10.1/crypto/openssl/ssl/t1_lib.c releng/10.1/sys/conf/newvers.sh releng/10.2/UPDATING releng/10.2/crypto/openssl/crypto/bn/bn_print.c releng/10.2/crypto/openssl/crypto/dsa/dsa_ossl.c releng/10.2/crypto/openssl/crypto/mdc2/mdc2dgst.c releng/10.2/crypto/openssl/crypto/ts/ts_lib.c releng/10.2/crypto/openssl/ssl/d1_both.c releng/10.2/crypto/openssl/ssl/d1_clnt.c releng/10.2/crypto/openssl/ssl/d1_lib.c releng/10.2/crypto/openssl/ssl/d1_pkt.c releng/10.2/crypto/openssl/ssl/d1_srvr.c releng/10.2/crypto/openssl/ssl/s3_clnt.c releng/10.2/crypto/openssl/ssl/s3_srvr.c releng/10.2/crypto/openssl/ssl/ssl.h releng/10.2/crypto/openssl/ssl/ssl_err.c releng/10.2/crypto/openssl/ssl/ssl_locl.h releng/10.2/crypto/openssl/ssl/ssl_sess.c releng/10.2/crypto/openssl/ssl/t1_lib.c releng/10.2/sys/conf/newvers.sh releng/10.3/UPDATING releng/10.3/crypto/openssl/crypto/bn/bn_print.c releng/10.3/crypto/openssl/crypto/dsa/dsa_ossl.c releng/10.3/crypto/openssl/crypto/mdc2/mdc2dgst.c releng/10.3/crypto/openssl/crypto/ts/ts_lib.c releng/10.3/crypto/openssl/ssl/d1_both.c releng/10.3/crypto/openssl/ssl/d1_clnt.c releng/10.3/crypto/openssl/ssl/d1_lib.c releng/10.3/crypto/openssl/ssl/d1_pkt.c releng/10.3/crypto/openssl/ssl/d1_srvr.c releng/10.3/crypto/openssl/ssl/s3_clnt.c releng/10.3/crypto/openssl/ssl/s3_srvr.c releng/10.3/crypto/openssl/ssl/ssl.h releng/10.3/crypto/openssl/ssl/ssl_err.c releng/10.3/crypto/openssl/ssl/ssl_locl.h releng/10.3/crypto/openssl/ssl/ssl_sess.c releng/10.3/crypto/openssl/ssl/t1_lib.c releng/10.3/sys/conf/newvers.sh releng/9.3/UPDATING releng/9.3/crypto/openssl/crypto/bn/bn_print.c releng/9.3/crypto/openssl/crypto/dsa/dsa_ossl.c releng/9.3/crypto/openssl/crypto/mdc2/mdc2dgst.c releng/9.3/crypto/openssl/ssl/d1_both.c releng/9.3/crypto/openssl/ssl/d1_clnt.c releng/9.3/crypto/openssl/ssl/d1_lib.c releng/9.3/crypto/openssl/ssl/d1_pkt.c releng/9.3/crypto/openssl/ssl/d1_srvr.c releng/9.3/crypto/openssl/ssl/s3_clnt.c releng/9.3/crypto/openssl/ssl/s3_srvr.c releng/9.3/crypto/openssl/ssl/ssl.h releng/9.3/crypto/openssl/ssl/ssl_err.c releng/9.3/crypto/openssl/ssl/ssl_locl.h releng/9.3/crypto/openssl/ssl/ssl_sess.c releng/9.3/crypto/openssl/ssl/t1_lib.c releng/9.3/sys/conf/newvers.sh Modified: releng/10.1/UPDATING ============================================================================== --- releng/10.1/UPDATING Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/UPDATING Fri Sep 23 07:48:34 2016 (r306230) @@ -16,6 +16,10 @@ from older versions of FreeBSD, try WITH stable/10, and then rebuild without this option. The bootstrap process from older version of current is a bit fragile. +20160923 p38 FreeBSD-SA-16:26.openssl + + Fix multiple OpenSSL vulnerabilitites. + 20160725 p37 FreeBSD-SA-16:25.bspatch FreeBSD-EN-16:09.freebsd-update Modified: releng/10.1/crypto/openssl/crypto/bn/bn_print.c ============================================================================== --- releng/10.1/crypto/openssl/crypto/bn/bn_print.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/crypto/bn/bn_print.c Fri Sep 23 07:48:34 2016 (r306230) @@ -111,6 +111,7 @@ char *BN_bn2dec(const BIGNUM *a) char *p; BIGNUM *t = NULL; BN_ULONG *bn_data = NULL, *lp; + int bn_data_num; /*- * get an upper bound for the length of the decimal integer @@ -120,8 +121,8 @@ char *BN_bn2dec(const BIGNUM *a) */ i = BN_num_bits(a) * 3; num = (i / 10 + i / 1000 + 1) + 1; - bn_data = - (BN_ULONG *)OPENSSL_malloc((num / BN_DEC_NUM + 1) * sizeof(BN_ULONG)); + bn_data_num = num / BN_DEC_NUM + 1; + bn_data = OPENSSL_malloc(bn_data_num * sizeof(BN_ULONG)); buf = (char *)OPENSSL_malloc(num + 3); if ((buf == NULL) || (bn_data == NULL)) { BNerr(BN_F_BN_BN2DEC, ERR_R_MALLOC_FAILURE); @@ -143,7 +144,11 @@ char *BN_bn2dec(const BIGNUM *a) i = 0; while (!BN_is_zero(t)) { *lp = BN_div_word(t, BN_DEC_CONV); + if (*lp == (BN_ULONG)-1) + goto err; lp++; + if (lp - bn_data >= bn_data_num) + goto err; } lp--; /* Modified: releng/10.1/crypto/openssl/crypto/dsa/dsa_ossl.c ============================================================================== --- releng/10.1/crypto/openssl/crypto/dsa/dsa_ossl.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/crypto/dsa/dsa_ossl.c Fri Sep 23 07:48:34 2016 (r306230) @@ -247,11 +247,13 @@ static int dsa_sign_setup(DSA *dsa, BN_C do if (!BN_rand_range(&k, dsa->q)) goto err; - while (BN_is_zero(&k)) ; + while (BN_is_zero(&k)); + if ((dsa->flags & DSA_FLAG_NO_EXP_CONSTTIME) == 0) { BN_set_flags(&k, BN_FLG_CONSTTIME); } + if (dsa->flags & DSA_FLAG_CACHE_MONT_P) { if (!BN_MONT_CTX_set_locked(&dsa->method_mont_p, CRYPTO_LOCK_DSA, dsa->p, ctx)) @@ -264,6 +266,8 @@ static int dsa_sign_setup(DSA *dsa, BN_C if (!BN_copy(&kq, &k)) goto err; + BN_set_flags(&kq, BN_FLG_CONSTTIME); + /* * We do not want timing information to leak the length of k, so we * compute g^k using an equivalent exponent of fixed length. (This @@ -282,6 +286,7 @@ static int dsa_sign_setup(DSA *dsa, BN_C } else { K = &k; } + DSA_BN_MOD_EXP(goto err, dsa, r, dsa->g, K, dsa->p, ctx, dsa->method_mont_p); if (!BN_mod(r, r, dsa->q, ctx)) Modified: releng/10.1/crypto/openssl/crypto/mdc2/mdc2dgst.c ============================================================================== --- releng/10.1/crypto/openssl/crypto/mdc2/mdc2dgst.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/crypto/mdc2/mdc2dgst.c Fri Sep 23 07:48:34 2016 (r306230) @@ -91,7 +91,7 @@ int MDC2_Update(MDC2_CTX *c, const unsig i = c->num; if (i != 0) { - if (i + len < MDC2_BLOCK) { + if (len < MDC2_BLOCK - i) { /* partial block */ memcpy(&(c->data[i]), in, len); c->num += (int)len; Modified: releng/10.1/crypto/openssl/crypto/ts/ts_lib.c ============================================================================== --- releng/10.1/crypto/openssl/crypto/ts/ts_lib.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/crypto/ts/ts_lib.c Fri Sep 23 07:48:34 2016 (r306230) @@ -90,9 +90,8 @@ int TS_OBJ_print_bio(BIO *bio, const ASN { char obj_txt[128]; - int len = OBJ_obj2txt(obj_txt, sizeof(obj_txt), obj, 0); - BIO_write(bio, obj_txt, len); - BIO_write(bio, "\n", 1); + OBJ_obj2txt(obj_txt, sizeof(obj_txt), obj, 0); + BIO_printf(bio, "%s\n", obj_txt); return 1; } Modified: releng/10.1/crypto/openssl/ssl/d1_both.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/d1_both.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/d1_both.c Fri Sep 23 07:48:34 2016 (r306230) @@ -586,11 +586,23 @@ static int dtls1_retrieve_buffered_fragm int al; *ok = 0; - item = pqueue_peek(s->d1->buffered_messages); - if (item == NULL) - return 0; + do { + item = pqueue_peek(s->d1->buffered_messages); + if (item == NULL) + return 0; + + frag = (hm_fragment *)item->data; + + if (frag->msg_header.seq < s->d1->handshake_read_seq) { + /* This is a stale message that has been buffered so clear it */ + pqueue_pop(s->d1->buffered_messages); + dtls1_hm_fragment_free(frag); + pitem_free(item); + item = NULL; + frag = NULL; + } + } while (item == NULL); - frag = (hm_fragment *)item->data; /* Don't return if reassembly still in progress */ if (frag->reassembly != NULL) @@ -1388,18 +1400,6 @@ dtls1_retransmit_message(SSL *s, unsigne return ret; } -/* call this function when the buffered messages are no longer needed */ -void dtls1_clear_record_buffer(SSL *s) -{ - pitem *item; - - for (item = pqueue_pop(s->d1->sent_messages); - item != NULL; item = pqueue_pop(s->d1->sent_messages)) { - dtls1_hm_fragment_free((hm_fragment *)item->data); - pitem_free(item); - } -} - unsigned char *dtls1_set_message_header(SSL *s, unsigned char *p, unsigned char mt, unsigned long len, unsigned long frag_off, Modified: releng/10.1/crypto/openssl/ssl/d1_clnt.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/d1_clnt.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/d1_clnt.c Fri Sep 23 07:48:34 2016 (r306230) @@ -740,6 +740,7 @@ int dtls1_connect(SSL *s) /* done with handshaking */ s->d1->handshake_read_seq = 0; s->d1->next_handshake_write_seq = 0; + dtls1_clear_received_buffer(s); goto end; /* break; */ Modified: releng/10.1/crypto/openssl/ssl/d1_lib.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/d1_lib.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/d1_lib.c Fri Sep 23 07:48:34 2016 (r306230) @@ -144,7 +144,6 @@ int dtls1_new(SSL *s) static void dtls1_clear_queues(SSL *s) { pitem *item = NULL; - hm_fragment *frag = NULL; DTLS1_RECORD_DATA *rdata; while ((item = pqueue_pop(s->d1->unprocessed_rcds.q)) != NULL) { @@ -165,28 +164,44 @@ static void dtls1_clear_queues(SSL *s) pitem_free(item); } + while ((item = pqueue_pop(s->d1->buffered_app_data.q)) != NULL) { + rdata = (DTLS1_RECORD_DATA *)item->data; + if (rdata->rbuf.buf) { + OPENSSL_free(rdata->rbuf.buf); + } + OPENSSL_free(item->data); + pitem_free(item); + } + + dtls1_clear_received_buffer(s); + dtls1_clear_sent_buffer(s); +} + +void dtls1_clear_received_buffer(SSL *s) +{ + pitem *item = NULL; + hm_fragment *frag = NULL; + while ((item = pqueue_pop(s->d1->buffered_messages)) != NULL) { frag = (hm_fragment *)item->data; dtls1_hm_fragment_free(frag); pitem_free(item); } +} + +void dtls1_clear_sent_buffer(SSL *s) +{ + pitem *item = NULL; + hm_fragment *frag = NULL; while ((item = pqueue_pop(s->d1->sent_messages)) != NULL) { frag = (hm_fragment *)item->data; dtls1_hm_fragment_free(frag); pitem_free(item); } - - while ((item = pqueue_pop(s->d1->buffered_app_data.q)) != NULL) { - rdata = (DTLS1_RECORD_DATA *)item->data; - if (rdata->rbuf.buf) { - OPENSSL_free(rdata->rbuf.buf); - } - OPENSSL_free(item->data); - pitem_free(item); - } } + void dtls1_free(SSL *s) { ssl3_free(s); @@ -420,7 +435,7 @@ void dtls1_stop_timer(SSL *s) BIO_ctrl(SSL_get_rbio(s), BIO_CTRL_DGRAM_SET_NEXT_TIMEOUT, 0, &(s->d1->next_timeout)); /* Clear retransmission buffer */ - dtls1_clear_record_buffer(s); + dtls1_clear_sent_buffer(s); } int dtls1_check_timeout_num(SSL *s) Modified: releng/10.1/crypto/openssl/ssl/d1_pkt.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/d1_pkt.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/d1_pkt.c Fri Sep 23 07:48:34 2016 (r306230) @@ -194,7 +194,7 @@ static int dtls1_record_needs_buffering( #endif static int dtls1_buffer_record(SSL *s, record_pqueue *q, unsigned char *priority); -static int dtls1_process_record(SSL *s); +static int dtls1_process_record(SSL *s, DTLS1_BITMAP *bitmap); /* copy buffered record into SSL structure */ static int dtls1_copy_record(SSL *s, pitem *item) @@ -319,21 +319,70 @@ static int dtls1_retrieve_buffered_recor static int dtls1_process_buffered_records(SSL *s) { pitem *item; + SSL3_BUFFER *rb; + SSL3_RECORD *rr; + DTLS1_BITMAP *bitmap; + unsigned int is_next_epoch; + int replayok = 1; item = pqueue_peek(s->d1->unprocessed_rcds.q); if (item) { /* Check if epoch is current. */ if (s->d1->unprocessed_rcds.epoch != s->d1->r_epoch) - return (1); /* Nothing to do. */ + return 1; /* Nothing to do. */ + + rr = &s->s3->rrec; + rb = &s->s3->rbuf; + + if (rb->left > 0) { + /* + * We've still got data from the current packet to read. There could + * be a record from the new epoch in it - so don't overwrite it + * with the unprocessed records yet (we'll do it when we've + * finished reading the current packet). + */ + return 1; + } + /* Process all the records. */ while (pqueue_peek(s->d1->unprocessed_rcds.q)) { dtls1_get_unprocessed_record(s); - if (!dtls1_process_record(s)) - return (0); + bitmap = dtls1_get_bitmap(s, rr, &is_next_epoch); + if (bitmap == NULL) { + /* + * Should not happen. This will only ever be NULL when the + * current record is from a different epoch. But that cannot + * be the case because we already checked the epoch above + */ + SSLerr(SSL_F_DTLS1_PROCESS_BUFFERED_RECORDS, + ERR_R_INTERNAL_ERROR); + return 0; + } +#ifndef OPENSSL_NO_SCTP + /* Only do replay check if no SCTP bio */ + if (!BIO_dgram_is_sctp(SSL_get_rbio(s))) +#endif + { + /* + * Check whether this is a repeat, or aged record. We did this + * check once already when we first received the record - but + * we might have updated the window since then due to + * records we subsequently processed. + */ + replayok = dtls1_record_replay_check(s, bitmap); + } + + if (!replayok || !dtls1_process_record(s, bitmap)) { + /* dump this record */ + rr->length = 0; + s->packet_length = 0; + continue; + } + if (dtls1_buffer_record(s, &(s->d1->processed_rcds), s->s3->rrec.seq_num) < 0) - return -1; + return 0; } } @@ -344,7 +393,7 @@ static int dtls1_process_buffered_record s->d1->processed_rcds.epoch = s->d1->r_epoch; s->d1->unprocessed_rcds.epoch = s->d1->r_epoch + 1; - return (1); + return 1; } #if 0 @@ -391,7 +440,7 @@ static int dtls1_get_buffered_record(SSL #endif -static int dtls1_process_record(SSL *s) +static int dtls1_process_record(SSL *s, DTLS1_BITMAP *bitmap) { int i, al; int enc_err; @@ -551,6 +600,10 @@ static int dtls1_process_record(SSL *s) /* we have pulled in a full packet so zero things */ s->packet_length = 0; + + /* Mark receipt of record. */ + dtls1_record_bitmap_update(s, bitmap); + return (1); f_err: @@ -581,11 +634,12 @@ int dtls1_get_record(SSL *s) rr = &(s->s3->rrec); + again: /* * The epoch may have changed. If so, process all the pending records. * This is a non-blocking operation. */ - if (dtls1_process_buffered_records(s) < 0) + if (!dtls1_process_buffered_records(s)) return -1; /* if we're renegotiating, then there may be buffered records */ @@ -593,7 +647,6 @@ int dtls1_get_record(SSL *s) return 1; /* get something from the wire */ - again: /* check if we have the header */ if ((s->rstate != SSL_ST_READ_BODY) || (s->packet_length < DTLS1_RT_HEADER_LENGTH)) { @@ -717,20 +770,17 @@ int dtls1_get_record(SSL *s) if (dtls1_buffer_record (s, &(s->d1->unprocessed_rcds), rr->seq_num) < 0) return -1; - /* Mark receipt of record. */ - dtls1_record_bitmap_update(s, bitmap); } rr->length = 0; s->packet_length = 0; goto again; } - if (!dtls1_process_record(s)) { + if (!dtls1_process_record(s, bitmap)) { rr->length = 0; s->packet_length = 0; /* dump this record */ goto again; /* get another record */ } - dtls1_record_bitmap_update(s, bitmap); /* Mark receipt of record. */ return (1); @@ -1814,8 +1864,13 @@ static DTLS1_BITMAP *dtls1_get_bitmap(SS if (rr->epoch == s->d1->r_epoch) return &s->d1->bitmap; - /* Only HM and ALERT messages can be from the next epoch */ + /* + * Only HM and ALERT messages can be from the next epoch and only if we + * have already processed all of the unprocessed records from the last + * epoch + */ else if (rr->epoch == (unsigned long)(s->d1->r_epoch + 1) && + s->d1->unprocessed_rcds.epoch != s->d1->r_epoch && (rr->type == SSL3_RT_HANDSHAKE || rr->type == SSL3_RT_ALERT)) { *is_next_epoch = 1; return &s->d1->next_bitmap; @@ -1894,6 +1949,12 @@ void dtls1_reset_seq_numbers(SSL *s, int s->d1->r_epoch++; memcpy(&(s->d1->bitmap), &(s->d1->next_bitmap), sizeof(DTLS1_BITMAP)); memset(&(s->d1->next_bitmap), 0x00, sizeof(DTLS1_BITMAP)); + + /* + * We must not use any buffered messages received from the previous + * epoch + */ + dtls1_clear_received_buffer(s); } else { seq = s->s3->write_sequence; memcpy(s->d1->last_write_sequence, seq, Modified: releng/10.1/crypto/openssl/ssl/d1_srvr.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/d1_srvr.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/d1_srvr.c Fri Sep 23 07:48:34 2016 (r306230) @@ -282,7 +282,7 @@ int dtls1_accept(SSL *s) case SSL3_ST_SW_HELLO_REQ_B: s->shutdown = 0; - dtls1_clear_record_buffer(s); + dtls1_clear_sent_buffer(s); dtls1_start_timer(s); ret = dtls1_send_hello_request(s); if (ret <= 0) @@ -845,6 +845,7 @@ int dtls1_accept(SSL *s) /* next message is server hello */ s->d1->handshake_write_seq = 0; s->d1->next_handshake_write_seq = 0; + dtls1_clear_received_buffer(s); goto end; /* break; */ Modified: releng/10.1/crypto/openssl/ssl/s3_clnt.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/s3_clnt.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/s3_clnt.c Fri Sep 23 07:48:34 2016 (r306230) @@ -1143,6 +1143,12 @@ int ssl3_get_server_certificate(SSL *s) goto f_err; } for (nc = 0; nc < llen;) { + if (nc + 3 > llen) { + al = SSL_AD_DECODE_ERROR; + SSLerr(SSL_F_SSL3_GET_SERVER_CERTIFICATE, + SSL_R_CERT_LENGTH_MISMATCH); + goto f_err; + } n2l3(p, l); if ((l + nc + 3) > llen) { al = SSL_AD_DECODE_ERROR; @@ -2046,6 +2052,11 @@ int ssl3_get_certificate_request(SSL *s) } for (nc = 0; nc < llen;) { + if (nc + 2 > llen) { + ssl3_send_alert(s, SSL3_AL_FATAL, SSL_AD_DECODE_ERROR); + SSLerr(SSL_F_SSL3_GET_CERTIFICATE_REQUEST, SSL_R_CA_DN_TOO_LONG); + goto err; + } n2s(p, l); if ((l + nc + 2) > llen) { if ((s->options & SSL_OP_NETSCAPE_CA_DN_BUG)) Modified: releng/10.1/crypto/openssl/ssl/s3_srvr.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/s3_srvr.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/s3_srvr.c Fri Sep 23 07:48:34 2016 (r306230) @@ -1041,7 +1041,7 @@ int ssl3_get_client_hello(SSL *s) session_length = *(p + SSL3_RANDOM_SIZE); - if (p + SSL3_RANDOM_SIZE + session_length + 1 >= d + n) { + if (SSL3_RANDOM_SIZE + session_length + 1 >= (d + n) - p) { al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_TOO_SHORT); goto f_err; @@ -1059,7 +1059,7 @@ int ssl3_get_client_hello(SSL *s) /* get the session-id */ j = *(p++); - if (p + j > d + n) { + if ((d + n) - p < j) { al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_TOO_SHORT); goto f_err; @@ -1109,14 +1109,14 @@ int ssl3_get_client_hello(SSL *s) if (s->version == DTLS1_VERSION || s->version == DTLS1_BAD_VER) { /* cookie stuff */ - if (p + 1 > d + n) { + if ((d + n) - p < 1) { al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_TOO_SHORT); goto f_err; } cookie_len = *(p++); - if (p + cookie_len > d + n) { + if ((d + n ) - p < cookie_len) { al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_TOO_SHORT); goto f_err; @@ -1162,7 +1162,7 @@ int ssl3_get_client_hello(SSL *s) p += cookie_len; } - if (p + 2 > d + n) { + if ((d + n ) - p < 2) { al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_TOO_SHORT); goto f_err; @@ -1176,7 +1176,7 @@ int ssl3_get_client_hello(SSL *s) } /* i bytes of cipher data + 1 byte for compression length later */ - if ((p + i + 1) > (d + n)) { + if ((d + n) - p < i + 1) { /* not enough data */ al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_MISMATCH); @@ -1242,7 +1242,7 @@ int ssl3_get_client_hello(SSL *s) /* compression */ i = *(p++); - if ((p + i) > (d + n)) { + if ((d + n) - p < i) { /* not enough data */ al = SSL_AD_DECODE_ERROR; SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_LENGTH_MISMATCH); @@ -1264,7 +1264,7 @@ int ssl3_get_client_hello(SSL *s) #ifndef OPENSSL_NO_TLSEXT /* TLS extensions */ if (s->version >= SSL3_VERSION) { - if (!ssl_parse_clienthello_tlsext(s, &p, d, n, &al)) { + if (!ssl_parse_clienthello_tlsext(s, &p, d + n, &al)) { /* 'al' set by ssl_parse_clienthello_tlsext */ SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, SSL_R_PARSE_TLSEXT); goto f_err; @@ -3218,6 +3218,12 @@ int ssl3_get_client_certificate(SSL *s) goto f_err; } for (nc = 0; nc < llen;) { + if (nc + 3 > llen) { + al = SSL_AD_DECODE_ERROR; + SSLerr(SSL_F_SSL3_GET_CLIENT_CERTIFICATE, + SSL_R_CERT_LENGTH_MISMATCH); + goto f_err; + } n2l3(p, l); if ((l + nc + 3) > llen) { al = SSL_AD_DECODE_ERROR; Modified: releng/10.1/crypto/openssl/ssl/ssl.h ============================================================================== --- releng/10.1/crypto/openssl/ssl/ssl.h Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/ssl.h Fri Sep 23 07:48:34 2016 (r306230) @@ -2256,6 +2256,7 @@ void ERR_load_SSL_strings(void); # define SSL_F_DTLS1_HEARTBEAT 305 # define SSL_F_DTLS1_OUTPUT_CERT_CHAIN 255 # define SSL_F_DTLS1_PREPROCESS_FRAGMENT 288 +# define SSL_F_DTLS1_PROCESS_BUFFERED_RECORDS 424 # define SSL_F_DTLS1_PROCESS_OUT_OF_SEQ_MESSAGE 256 # define SSL_F_DTLS1_PROCESS_RECORD 257 # define SSL_F_DTLS1_READ_BYTES 258 Modified: releng/10.1/crypto/openssl/ssl/ssl_err.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/ssl_err.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/ssl_err.c Fri Sep 23 07:48:34 2016 (r306230) @@ -1,6 +1,6 @@ /* ssl/ssl_err.c */ /* ==================================================================== - * Copyright (c) 1999-2011 The OpenSSL Project. All rights reserved. + * Copyright (c) 1999-2016 The OpenSSL Project. All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions @@ -93,6 +93,8 @@ static ERR_STRING_DATA SSL_str_functs[] {ERR_FUNC(SSL_F_DTLS1_HEARTBEAT), "DTLS1_HEARTBEAT"}, {ERR_FUNC(SSL_F_DTLS1_OUTPUT_CERT_CHAIN), "DTLS1_OUTPUT_CERT_CHAIN"}, {ERR_FUNC(SSL_F_DTLS1_PREPROCESS_FRAGMENT), "DTLS1_PREPROCESS_FRAGMENT"}, + {ERR_FUNC(SSL_F_DTLS1_PROCESS_BUFFERED_RECORDS), + "DTLS1_PROCESS_BUFFERED_RECORDS"}, {ERR_FUNC(SSL_F_DTLS1_PROCESS_OUT_OF_SEQ_MESSAGE), "DTLS1_PROCESS_OUT_OF_SEQ_MESSAGE"}, {ERR_FUNC(SSL_F_DTLS1_PROCESS_RECORD), "DTLS1_PROCESS_RECORD"}, Modified: releng/10.1/crypto/openssl/ssl/ssl_locl.h ============================================================================== --- releng/10.1/crypto/openssl/ssl/ssl_locl.h Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/ssl_locl.h Fri Sep 23 07:48:34 2016 (r306230) @@ -1025,7 +1025,8 @@ int dtls1_retransmit_message(SSL *s, uns unsigned long frag_off, int *found); int dtls1_get_queue_priority(unsigned short seq, int is_ccs); int dtls1_retransmit_buffered_messages(SSL *s); -void dtls1_clear_record_buffer(SSL *s); +void dtls1_clear_received_buffer(SSL *s); +void dtls1_clear_sent_buffer(SSL *s); void dtls1_get_message_header(unsigned char *data, struct hm_header_st *msg_hdr); void dtls1_get_ccs_header(unsigned char *data, struct ccs_header_st *ccs_hdr); @@ -1154,7 +1155,7 @@ unsigned char *ssl_add_clienthello_tlsex unsigned char *ssl_add_serverhello_tlsext(SSL *s, unsigned char *buf, unsigned char *limit); int ssl_parse_clienthello_tlsext(SSL *s, unsigned char **data, - unsigned char *d, int n, int *al); + unsigned char *limit, int *al); int ssl_parse_serverhello_tlsext(SSL *s, unsigned char **data, unsigned char *d, int n, int *al); int ssl_prepare_clienthello_tlsext(SSL *s); Modified: releng/10.1/crypto/openssl/ssl/ssl_sess.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/ssl_sess.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/ssl_sess.c Fri Sep 23 07:48:34 2016 (r306230) @@ -605,7 +605,7 @@ int ssl_get_prev_session(SSL *s, unsigne if (len < 0 || len > SSL_MAX_SSL_SESSION_ID_LENGTH) goto err; - if (session_id + len > limit) { + if (limit - session_id < len) { fatal = 1; goto err; } Modified: releng/10.1/crypto/openssl/ssl/t1_lib.c ============================================================================== --- releng/10.1/crypto/openssl/ssl/t1_lib.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/crypto/openssl/ssl/t1_lib.c Fri Sep 23 07:48:34 2016 (r306230) @@ -913,7 +913,7 @@ unsigned char *ssl_add_serverhello_tlsex * 10.8..10.8.3 (which don't work). */ static void ssl_check_for_safari(SSL *s, const unsigned char *data, - const unsigned char *d, int n) + const unsigned char *limit) { unsigned short type, size; static const unsigned char kSafariExtensionsBlock[] = { @@ -942,11 +942,11 @@ static void ssl_check_for_safari(SSL *s, 0x02, 0x03, /* SHA-1/ECDSA */ }; - if (data >= (d + n - 2)) + if (limit - data <= 2) return; data += 2; - if (data > (d + n - 4)) + if (limit - data < 4) return; n2s(data, type); n2s(data, size); @@ -954,7 +954,7 @@ static void ssl_check_for_safari(SSL *s, if (type != TLSEXT_TYPE_server_name) return; - if (data + size > d + n) + if (limit - data < size) return; data += size; @@ -962,7 +962,7 @@ static void ssl_check_for_safari(SSL *s, const size_t len1 = sizeof(kSafariExtensionsBlock); const size_t len2 = sizeof(kSafariTLS12ExtensionsBlock); - if (data + len1 + len2 != d + n) + if (limit - data != (int)(len1 + len2)) return; if (memcmp(data, kSafariExtensionsBlock, len1) != 0) return; @@ -971,7 +971,7 @@ static void ssl_check_for_safari(SSL *s, } else { const size_t len = sizeof(kSafariExtensionsBlock); - if (data + len != d + n) + if (limit - data != (int)(len)) return; if (memcmp(data, kSafariExtensionsBlock, len) != 0) return; @@ -981,8 +981,8 @@ static void ssl_check_for_safari(SSL *s, } # endif /* !OPENSSL_NO_EC */ -int ssl_parse_clienthello_tlsext(SSL *s, unsigned char **p, unsigned char *d, - int n, int *al) +int ssl_parse_clienthello_tlsext(SSL *s, unsigned char **p, + unsigned char *limit, int *al) { unsigned short type; unsigned short size; @@ -1004,7 +1004,7 @@ int ssl_parse_clienthello_tlsext(SSL *s, # ifndef OPENSSL_NO_EC if (s->options & SSL_OP_SAFARI_ECDHE_ECDSA_BUG) - ssl_check_for_safari(s, data, d, n); + ssl_check_for_safari(s, data, limit); # endif /* !OPENSSL_NO_EC */ # ifndef OPENSSL_NO_SRP @@ -1016,22 +1016,22 @@ int ssl_parse_clienthello_tlsext(SSL *s, s->srtp_profile = NULL; - if (data == d + n) + if (data == limit) goto ri_check; - if (data > (d + n - 2)) + if (limit - data < 2) goto err; n2s(data, len); - if (data > (d + n - len)) + if (limit - data != len) goto err; - while (data <= (d + n - 4)) { + while (limit - data >= 4) { n2s(data, type); n2s(data, size); - if (data + size > (d + n)) + if (limit - data < size) goto err; # if 0 fprintf(stderr, "Received extension type %d size %d\n", type, size); @@ -1284,6 +1284,23 @@ int ssl_parse_clienthello_tlsext(SSL *s, size -= 2; if (dsize > size) goto err; + + /* + * We remove any OCSP_RESPIDs from a previous handshake + * to prevent unbounded memory growth - CVE-2016-6304 + */ + sk_OCSP_RESPID_pop_free(s->tlsext_ocsp_ids, + OCSP_RESPID_free); + if (dsize > 0) { + s->tlsext_ocsp_ids = sk_OCSP_RESPID_new_null(); + if (s->tlsext_ocsp_ids == NULL) { + *al = SSL_AD_INTERNAL_ERROR; + return 0; + } + } else { + s->tlsext_ocsp_ids = NULL; + } + while (dsize > 0) { OCSP_RESPID *id; int idsize; @@ -1303,13 +1320,6 @@ int ssl_parse_clienthello_tlsext(SSL *s, OCSP_RESPID_free(id); goto err; } - if (!s->tlsext_ocsp_ids - && !(s->tlsext_ocsp_ids = - sk_OCSP_RESPID_new_null())) { - OCSP_RESPID_free(id); - *al = SSL_AD_INTERNAL_ERROR; - return 0; - } if (!sk_OCSP_RESPID_push(s->tlsext_ocsp_ids, id)) { OCSP_RESPID_free(id); *al = SSL_AD_INTERNAL_ERROR; @@ -1396,7 +1406,7 @@ int ssl_parse_clienthello_tlsext(SSL *s, } /* Spurious data on the end */ - if (data != d + n) + if (data != limit) goto err; *p = data; @@ -1460,20 +1470,20 @@ int ssl_parse_serverhello_tlsext(SSL *s, SSL_TLSEXT_HB_DONT_SEND_REQUESTS); # endif - if (data >= (d + n - 2)) + if ((d + n) - data <= 2) goto ri_check; n2s(data, length); - if (data + length != d + n) { + if ((d + n) - data != length) { *al = SSL_AD_DECODE_ERROR; return 0; } - while (data <= (d + n - 4)) { + while ((d + n) - data >= 4) { n2s(data, type); n2s(data, size); - if (data + size > (d + n)) + if ((d + n) - data < size) goto ri_check; if (s->tlsext_debug_cb) @@ -2181,29 +2191,33 @@ int tls1_process_ticket(SSL *s, unsigned /* Skip past DTLS cookie */ if (s->version == DTLS1_VERSION || s->version == DTLS1_BAD_VER) { i = *(p++); - p += i; - if (p >= limit) + + if (limit - p <= i) return -1; + + p += i; } /* Skip past cipher list */ n2s(p, i); - p += i; - if (p >= limit) + if (limit - p <= i) return -1; + p += i; + /* Skip past compression algorithm list */ i = *(p++); - p += i; - if (p > limit) + if (limit - p < i) return -1; + p += i; + /* Now at start of extensions */ - if ((p + 2) >= limit) + if (limit - p <= 2) return 0; n2s(p, i); - while ((p + 4) <= limit) { + while (limit - p >= 4) { unsigned short type, size; n2s(p, type); n2s(p, size); - if (p + size > limit) + if (limit - p < size) return 0; if (type == TLSEXT_TYPE_session_ticket) { int r; @@ -2271,9 +2285,7 @@ static int tls_decrypt_ticket(SSL *s, co HMAC_CTX hctx; EVP_CIPHER_CTX ctx; SSL_CTX *tctx = s->initial_ctx; - /* Need at least keyname + iv + some encrypted data */ - if (eticklen < 48) - return 2; + /* Initialize session ticket encryption and HMAC contexts */ HMAC_CTX_init(&hctx); EVP_CIPHER_CTX_init(&ctx); @@ -2305,6 +2317,13 @@ static int tls_decrypt_ticket(SSL *s, co EVP_CIPHER_CTX_cleanup(&ctx); return -1; } + /* Sanity check ticket length: must exceed keyname + IV + HMAC */ + if (eticklen <= 16 + EVP_CIPHER_CTX_iv_length(&ctx) + mlen) { + HMAC_CTX_cleanup(&hctx); + EVP_CIPHER_CTX_cleanup(&ctx); + return 2; + } + eticklen -= mlen; /* Check HMAC of encrypted ticket */ HMAC_Update(&hctx, etick, eticklen); Modified: releng/10.1/sys/conf/newvers.sh ============================================================================== --- releng/10.1/sys/conf/newvers.sh Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.1/sys/conf/newvers.sh Fri Sep 23 07:48:34 2016 (r306230) @@ -32,7 +32,7 @@ TYPE="FreeBSD" REVISION="10.1" -BRANCH="RELEASE-p37" +BRANCH="RELEASE-p38" if [ "X${BRANCH_OVERRIDE}" != "X" ]; then BRANCH=${BRANCH_OVERRIDE} fi Modified: releng/10.2/UPDATING ============================================================================== --- releng/10.2/UPDATING Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/UPDATING Fri Sep 23 07:48:34 2016 (r306230) @@ -16,6 +16,10 @@ from older versions of FreeBSD, try WITH stable/10, and then rebuild without this option. The bootstrap process from older version of current is a bit fragile. +20160923 p21 FreeBSD-SA-16:26.openssl + + Fix multiple OpenSSL vulnerabilitites. + 20160725 p20 FreeBSD-SA-16:25.bspatch FreeBSD-EN-16:09.freebsd-update Modified: releng/10.2/crypto/openssl/crypto/bn/bn_print.c ============================================================================== --- releng/10.2/crypto/openssl/crypto/bn/bn_print.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/crypto/openssl/crypto/bn/bn_print.c Fri Sep 23 07:48:34 2016 (r306230) @@ -111,6 +111,7 @@ char *BN_bn2dec(const BIGNUM *a) char *p; BIGNUM *t = NULL; BN_ULONG *bn_data = NULL, *lp; + int bn_data_num; /*- * get an upper bound for the length of the decimal integer @@ -120,8 +121,8 @@ char *BN_bn2dec(const BIGNUM *a) */ i = BN_num_bits(a) * 3; num = (i / 10 + i / 1000 + 1) + 1; - bn_data = - (BN_ULONG *)OPENSSL_malloc((num / BN_DEC_NUM + 1) * sizeof(BN_ULONG)); + bn_data_num = num / BN_DEC_NUM + 1; + bn_data = OPENSSL_malloc(bn_data_num * sizeof(BN_ULONG)); buf = (char *)OPENSSL_malloc(num + 3); if ((buf == NULL) || (bn_data == NULL)) { BNerr(BN_F_BN_BN2DEC, ERR_R_MALLOC_FAILURE); @@ -143,7 +144,11 @@ char *BN_bn2dec(const BIGNUM *a) i = 0; while (!BN_is_zero(t)) { *lp = BN_div_word(t, BN_DEC_CONV); + if (*lp == (BN_ULONG)-1) + goto err; lp++; + if (lp - bn_data >= bn_data_num) + goto err; } lp--; /* Modified: releng/10.2/crypto/openssl/crypto/dsa/dsa_ossl.c ============================================================================== --- releng/10.2/crypto/openssl/crypto/dsa/dsa_ossl.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/crypto/openssl/crypto/dsa/dsa_ossl.c Fri Sep 23 07:48:34 2016 (r306230) @@ -247,11 +247,13 @@ static int dsa_sign_setup(DSA *dsa, BN_C do if (!BN_rand_range(&k, dsa->q)) goto err; - while (BN_is_zero(&k)) ; + while (BN_is_zero(&k)); + if ((dsa->flags & DSA_FLAG_NO_EXP_CONSTTIME) == 0) { BN_set_flags(&k, BN_FLG_CONSTTIME); } + if (dsa->flags & DSA_FLAG_CACHE_MONT_P) { if (!BN_MONT_CTX_set_locked(&dsa->method_mont_p, CRYPTO_LOCK_DSA, dsa->p, ctx)) @@ -264,6 +266,8 @@ static int dsa_sign_setup(DSA *dsa, BN_C if (!BN_copy(&kq, &k)) goto err; + BN_set_flags(&kq, BN_FLG_CONSTTIME); + /* * We do not want timing information to leak the length of k, so we * compute g^k using an equivalent exponent of fixed length. (This @@ -282,6 +286,7 @@ static int dsa_sign_setup(DSA *dsa, BN_C } else { K = &k; } + DSA_BN_MOD_EXP(goto err, dsa, r, dsa->g, K, dsa->p, ctx, dsa->method_mont_p); if (!BN_mod(r, r, dsa->q, ctx)) Modified: releng/10.2/crypto/openssl/crypto/mdc2/mdc2dgst.c ============================================================================== --- releng/10.2/crypto/openssl/crypto/mdc2/mdc2dgst.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/crypto/openssl/crypto/mdc2/mdc2dgst.c Fri Sep 23 07:48:34 2016 (r306230) @@ -91,7 +91,7 @@ int MDC2_Update(MDC2_CTX *c, const unsig i = c->num; if (i != 0) { - if (i + len < MDC2_BLOCK) { + if (len < MDC2_BLOCK - i) { /* partial block */ memcpy(&(c->data[i]), in, len); c->num += (int)len; Modified: releng/10.2/crypto/openssl/crypto/ts/ts_lib.c ============================================================================== --- releng/10.2/crypto/openssl/crypto/ts/ts_lib.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/crypto/openssl/crypto/ts/ts_lib.c Fri Sep 23 07:48:34 2016 (r306230) @@ -90,9 +90,8 @@ int TS_OBJ_print_bio(BIO *bio, const ASN { char obj_txt[128]; - int len = OBJ_obj2txt(obj_txt, sizeof(obj_txt), obj, 0); - BIO_write(bio, obj_txt, len); - BIO_write(bio, "\n", 1); + OBJ_obj2txt(obj_txt, sizeof(obj_txt), obj, 0); + BIO_printf(bio, "%s\n", obj_txt); return 1; } Modified: releng/10.2/crypto/openssl/ssl/d1_both.c ============================================================================== --- releng/10.2/crypto/openssl/ssl/d1_both.c Fri Sep 23 07:44:10 2016 (r306229) +++ releng/10.2/crypto/openssl/ssl/d1_both.c Fri Sep 23 07:48:34 2016 (r306230) @@ -586,11 +586,23 @@ static int dtls1_retrieve_buffered_fragm int al; *ok = 0; - item = pqueue_peek(s->d1->buffered_messages); - if (item == NULL) - return 0; + do { + item = pqueue_peek(s->d1->buffered_messages); + if (item == NULL) + return 0; + + frag = (hm_fragment *)item->data; + + if (frag->msg_header.seq < s->d1->handshake_read_seq) { + /* This is a stale message that has been buffered so clear it */ + pqueue_pop(s->d1->buffered_messages); + dtls1_hm_fragment_free(frag); + pitem_free(item); + item = NULL; + frag = NULL; + } + } while (item == NULL); - frag = (hm_fragment *)item->data; *** DIFF OUTPUT TRUNCATED AT 1000 LINES ***