Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Feb 2021 15:06:08 -0500
From:      Ed Maste <emaste@freebsd.org>
To:        Kevin Oberman <rkoberman@gmail.com>
Cc:        FreeBSD-STABLE Mailing List <freebsd-stable@freebsd.org>
Subject:   Re: How do I know if my 13-stable has security patches?
Message-ID:  <CAPyFy2Dg9dP5%2BCWvmUhf58b4KotqrtWRt%2BnrZjoiNnzY5mk-eg@mail.gmail.com>
In-Reply-To: <CAN6yY1tTt%2BEn6hzMYrjm2fRkUPBAuN9t8%2BR27Z3To_sJRbfUVA@mail.gmail.com>
References:  <CAN6yY1tTt%2BEn6hzMYrjm2fRkUPBAuN9t8%2BR27Z3To_sJRbfUVA@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 24 Feb 2021 at 12:35, Kevin Oberman <rkoberman@gmail.com> wrote:
>
> In the svn days, I could just look at my svn revision to check on whether a
> security patch was required. Now I have a git hash. I have no idea how to
> tell if my system running 13-STABLE of a few days ago has the patch.

Thanks for posting this question. I see some useful information in
other replies to this thread and we'll want to make sure that makes
its way to appropriate documentation.

For future advisories we should also report the commit count
associated with the fix; this is a monotonically-increasing number and
is reported in the uname.

If you build stable/13 right now you would get
"stable/13-n244668-4664afc05402", and the fix in
894360bacd42f021551f76518edd445f6d299f2e corresponds to n244572.
244668 being larger than 244572 indicates that the fix is included.

These counts are not unique across different branches; you can only
compare counts for the same branch.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAPyFy2Dg9dP5%2BCWvmUhf58b4KotqrtWRt%2BnrZjoiNnzY5mk-eg>