svn commit: r320583 - stable/9/lib/libc/rpc

2017-07-02 Thread Xin LI
Author: delphij Date: Mon Jul 3 02:18:10 2017 New Revision: 320583 URL: https://svnweb.freebsd.org/changeset/base/320583 Log: MFC r320494: Fix double free by reverting r300385 and r300624 which was false positive reported by cppcheck. Modified: stable/9/lib/libc/rpc/getnetconfig.c

svn commit: r309849 - in stable/9: contrib/file contrib/file/doc contrib/file/magic contrib/file/magic/Magdir contrib/file/python contrib/file/src lib/libmagic

2016-12-10 Thread Xin LI
Author: delphij Date: Sun Dec 11 07:39:10 2016 New Revision: 309849 URL: https://svnweb.freebsd.org/changeset/base/309849 Log: MFC r308420: MFV r308392: file 5.29. Added: stable/9/contrib/file/magic/Magdir/algol68 - copied unchanged from r308420, head/contrib/file/magic/Magdir/algol68

svn commit: r309009 - in stable/9: contrib/ntp contrib/ntp/html contrib/ntp/html/drivers contrib/ntp/include contrib/ntp/lib/isc contrib/ntp/libntp contrib/ntp/libparse contrib/ntp/ntpd contrib/ntp...

2016-11-22 Thread Xin LI
Author: delphij Date: Tue Nov 22 16:23:46 2016 New Revision: 309009 URL: https://svnweb.freebsd.org/changeset/base/309009 Log: MFC r308957: MFV r308954: ntp 4.2.8p9. Approved by: so Added: stable/9/contrib/ntp/include/libssl_compat.h - copied unchanged from r308957,

svn commit: r308200 - in stable: 10/crypto/openssl/ssl 9/crypto/openssl/ssl

2016-11-02 Thread Xin LI
Author: delphij Date: Wed Nov 2 07:09:31 2016 New Revision: 308200 URL: https://svnweb.freebsd.org/changeset/base/308200 Log: Backport OpenSSL commit af58be768ebb690f78530f796e92b8ae5c9a4401: Don't allow too many consecutive warning alerts Certain warning alerts are ignored if

svn commit: r308193 - in stable/9: contrib/bind9 contrib/bind9/doc/arm contrib/bind9/lib/dns lib/bind

2016-11-01 Thread Xin LI
Author: delphij Date: Wed Nov 2 05:13:27 2016 New Revision: 308193 URL: https://svnweb.freebsd.org/changeset/base/308193 Log: MFV r308191: BIND 9.9.9-P4. Modified: stable/9/contrib/bind9/CHANGES stable/9/contrib/bind9/README stable/9/contrib/bind9/doc/arm/Bv9ARM.ch01.html

svn commit: r306394 - in stable/9: contrib/bind9 contrib/bind9/bin/check contrib/bind9/bin/confgen contrib/bind9/bin/dig contrib/bind9/bin/dnssec contrib/bind9/bin/named contrib/bind9/bin/named/inc...

2016-09-28 Thread Xin LI
Author: delphij Date: Wed Sep 28 06:11:01 2016 New Revision: 306394 URL: https://svnweb.freebsd.org/changeset/base/306394 Log: MFV r306384: BIND 9.9.9-P3. Added: stable/9/contrib/bind9/doc/arm/Bv9ARM.conf - copied unchanged from r306384, vendor/bind9/dist/doc/arm/Bv9ARM.conf

svn commit: r306335 - stable/9/crypto/openssl/crypto/bn

2016-09-26 Thread Xin LI
Author: delphij Date: Mon Sep 26 08:19:33 2016 New Revision: 306335 URL: https://svnweb.freebsd.org/changeset/base/306335 Log: Apply upstream revision 3612ff6fcec0e3d1f2a598135fe12177c0419582: Fix overflow check in BN_bn2dec() Fix an off by one error in the overflow check added by

svn commit: r306229 - in stable/9/crypto/openssl: crypto/bn crypto/dsa crypto/mdc2 ssl

2016-09-23 Thread Xin LI
Author: delphij Date: Fri Sep 23 07:44:10 2016 New Revision: 306229 URL: https://svnweb.freebsd.org/changeset/base/306229 Log: Fix multiple OpenSSL vulnerabilities. Security: FreeBSD-SA-16:26.openssl Modified: stable/9/crypto/openssl/crypto/bn/bn_print.c

svn commit: r305650 - stable/9/usr.sbin/portsnap/portsnap

2016-09-09 Thread Xin LI
Author: delphij Date: Fri Sep 9 07:00:50 2016 New Revision: 305650 URL: https://svnweb.freebsd.org/changeset/base/305650 Log: MFC r305469: Ensure that we always open only files that is named by explicitly using shell redirections instead of having gzip(1) to decide what file to open.

svn commit: r303301 - in stable: 10/usr.bin/bsdiff/bspatch 9/usr.bin/bsdiff/bspatch

2016-07-25 Thread Xin LI
Author: delphij Date: Mon Jul 25 14:53:04 2016 New Revision: 303301 URL: https://svnweb.freebsd.org/changeset/base/303301 Log: Fix bspatch heap overflow vulnerability. Obtained from:Chromium Reported by: Lu Tung-Pin Security: FreeBSD-SA-16:25.bspatch Modified:

svn commit: r303286 - in stable/9: contrib/file contrib/file/doc contrib/file/magic contrib/file/magic/Magdir contrib/file/src lib/libmagic

2016-07-24 Thread Xin LI
Author: delphij Date: Mon Jul 25 05:33:19 2016 New Revision: 303286 URL: https://svnweb.freebsd.org/changeset/base/303286 Log: MFC r302221,30: MFV r302218: file 5.28. Relnotes: yes Added: stable/9/contrib/file/magic/Magdir/ber - copied unchanged from r302221,

svn commit: r303281 - stable/9/usr.bin/mail

2016-07-24 Thread Xin LI
Author: delphij Date: Mon Jul 25 00:46:45 2016 New Revision: 303281 URL: https://svnweb.freebsd.org/changeset/base/303281 Log: MFC r302542: Use _PATH_DEVNULL instead of hardcoding. Modified: stable/9/usr.bin/mail/collect.c Directory Properties: stable/9/usr.bin/mail/ (props changed)

svn commit: r302537 - stable/9/usr.sbin/freebsd-update

2016-07-10 Thread Xin LI
Author: delphij Date: Mon Jul 11 04:12:15 2016 New Revision: 302537 URL: https://svnweb.freebsd.org/changeset/base/302537 Log: MFC r302534: Allow - in distribution names. This is needed for freebsd-update to work with 11.0+, where the debugging symbols use a new naming scheme for

svn commit: r302386 - in stable/9/contrib/expat: . doc examples lib tests tests/benchmark xmlwf

2016-07-06 Thread Xin LI
Author: delphij Date: Thu Jul 7 05:04:20 2016 New Revision: 302386 URL: https://svnweb.freebsd.org/changeset/base/302386 Log: MFC r302305: MFV r302260: expat 2.2.0. Added: stable/9/contrib/expat/configure.ac - copied unchanged from r302305, head/contrib/expat/configure.ac

svn commit: r301825 - stable/9/release/scripts

2016-06-10 Thread Xin LI
Author: delphij Date: Sat Jun 11 05:58:51 2016 New Revision: 301825 URL: https://svnweb.freebsd.org/changeset/base/301825 Log: MFC r301584: Apply mergemaster r255428: Pass -n (do not emit comments) when saving mtree information for future mergemaster(8) runs. Modified:

svn commit: r301257 - in stable/9: contrib/ntp contrib/ntp/html contrib/ntp/include contrib/ntp/ntpd contrib/ntp/ntpdc contrib/ntp/ntpq contrib/ntp/ntpsnmpd contrib/ntp/scripts contrib/ntp/scripts/...

2016-06-03 Thread Xin LI
Author: delphij Date: Fri Jun 3 09:03:10 2016 New Revision: 301257 URL: https://svnweb.freebsd.org/changeset/base/301257 Log: MFC r301247: MFV r301238: ntp 4.2.8p8. Security: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954 Security: CVE-2016-4955, CVE-2016-4956 Security:

svn commit: r300900 - in stable/9: contrib/file contrib/file/doc contrib/file/magic contrib/file/magic/Magdir contrib/file/python contrib/file/src contrib/file/tests lib/libmagic

2016-05-28 Thread Xin LI
Author: delphij Date: Sat May 28 06:24:48 2016 New Revision: 300900 URL: https://svnweb.freebsd.org/changeset/base/300900 Log: MFC r298192,299234,299238,299736: file 5.27. Added: stable/9/contrib/file/magic/Magdir/bioinformatics - copied unchanged from r298192,

svn commit: r299053 - in stable/9/crypto/openssl/crypto: asn1 evp x509

2016-05-04 Thread Xin LI
Author: delphij Date: Wed May 4 06:53:02 2016 New Revision: 299053 URL: https://svnweb.freebsd.org/changeset/base/299053 Log: Fix several OpenSSL vulnerabilities. Security: CVE-2016-2105, CVE-2016-2106, CVE-2016-2109 Security: CVE-2016-2176 (does not affect FreeBSD) Security:

svn commit: r298700 - in stable/9: contrib/ntp contrib/ntp/html contrib/ntp/include contrib/ntp/lib/isc contrib/ntp/lib/isc/include/isc contrib/ntp/libntp contrib/ntp/ntpd contrib/ntp/ntpdate contr...

2016-04-27 Thread Xin LI
Author: delphij Date: Wed Apr 27 15:25:18 2016 New Revision: 298700 URL: https://svnweb.freebsd.org/changeset/base/298700 Log: MFC r298695: MFV r298691: ntp 4.2.8p7. Security: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550 Security: CVE-2016-1551, CVE-2016-2516,

svn commit: r298198 - in stable/9: contrib/file contrib/file/doc contrib/file/magic/Magdir contrib/file/src lib/libmagic

2016-04-18 Thread Xin LI
Author: delphij Date: Mon Apr 18 08:30:52 2016 New Revision: 298198 URL: https://svnweb.freebsd.org/changeset/base/298198 Log: MFC r287453,287454,288143: file 5.25. Modified: stable/9/contrib/file/ChangeLog stable/9/contrib/file/configure stable/9/contrib/file/configure.ac

svn commit: r296608 - in stable/9/contrib/bind9: . bin/named bin/rndc doc/arm lib/dns lib/isccc

2016-03-09 Thread Xin LI
Author: delphij Date: Thu Mar 10 07:44:56 2016 New Revision: 296608 URL: https://svnweb.freebsd.org/changeset/base/296608 Log: MFV r296599: BIND 9.9.8-P4. Security: CVE-2016-1285 Security: CVE-2016-1286 Security: CVE-2016-2088 Security: FreeBSD-SA-16:13.bind

svn commit: r296598 - stable/9/crypto/openssl/crypto/bn

2016-03-09 Thread Xin LI
Author: delphij Date: Thu Mar 10 03:58:48 2016 New Revision: 296598 URL: https://svnweb.freebsd.org/changeset/base/296598 Log: Fix CR/LF's in bn_exp.c introduced in r207783. No actual code change. Modified: stable/9/crypto/openssl/crypto/bn/bn_exp.c Modified:

svn commit: r296597 - stable/9/crypto/openssl/crypto/bn

2016-03-09 Thread Xin LI
Author: delphij Date: Thu Mar 10 03:57:37 2016 New Revision: 296597 URL: https://svnweb.freebsd.org/changeset/base/296597 Log: Fix a regression introduced in r296462 that causes out-of-bound access in the BN code and have slipped my review. PR: 207783 Submitted by: dim

svn commit: r296462 - in stable/9: crypto/openssl/crypto/bio crypto/openssl/crypto/bn crypto/openssl/doc/apps crypto/openssl/ssl secure/usr.bin/openssl/man

2016-03-07 Thread Xin LI
Author: delphij Date: Mon Mar 7 16:18:07 2016 New Revision: 296462 URL: https://svnweb.freebsd.org/changeset/base/296462 Log: Fix multiple OpenSSL vulnerabilities as published in OpenSSL advisory on 2016/03/01: constant-time MOD_EXP_CTIME_COPY_FROM_PREBUF. [CVE-2016-0702, upstream

svn commit: r295915 - stable/9/contrib/libarchive/libarchive

2016-02-23 Thread Xin LI
Author: delphij Date: Tue Feb 23 08:12:39 2016 New Revision: 295915 URL: https://svnweb.freebsd.org/changeset/base/295915 Log: Instant-MFC r295914: MFV r295913: Partially apply upstream changeset 6e06b1c8 (kientzle). Limit filter recursion level to 25 (instead of infinite). This

svn commit: r295060 - stable/9/crypto/openssl/ssl

2016-01-29 Thread Xin LI
Author: delphij Date: Sat Jan 30 06:09:38 2016 New Revision: 295060 URL: https://svnweb.freebsd.org/changeset/base/295060 Log: Fix OpenSSL SSLv2 ciphersuite downgrade vulnerability. Security: CVE-2015-3197 Security: FreeBSD-SA-16:11.openssl Modified:

svn commit: r294903 - in stable/9/sys: amd64/linux32 dev/usb/wlan i386/linux

2016-01-26 Thread Xin LI
Author: delphij Date: Wed Jan 27 07:34:23 2016 New Revision: 294903 URL: https://svnweb.freebsd.org/changeset/base/294903 Log: MFC r294900: Implement AT_SECURE properly. AT_SECURE auxv entry has been added to the Linux 2.5 kernel to pass a boolean flag indicating whether secure mode

svn commit: r294570 - in stable/9: contrib/ntp contrib/ntp/html contrib/ntp/include contrib/ntp/libntp contrib/ntp/ntpd contrib/ntp/ntpdc contrib/ntp/ntpq contrib/ntp/ntpsnmpd contrib/ntp/scripts c...

2016-01-22 Thread Xin LI
Author: delphij Date: Fri Jan 22 15:56:35 2016 New Revision: 294570 URL: https://svnweb.freebsd.org/changeset/base/294570 Log: MFC r294554: MFV r294491: ntp 4.2.8p6. Security: CVE-2015-7973, CVE-2015-7974, CVE-2015-7975 Security: CVE-2015-7976, CVE-2015-7977, CVE-2015-7978

svn commit: r294405 - in stable/9: contrib/bind9 contrib/bind9/doc/arm contrib/bind9/lib/dns contrib/bind9/lib/dns/rdata/in_1 lib/bind/dns lib/bind/dns/dns

2016-01-20 Thread Xin LI
Author: delphij Date: Wed Jan 20 08:54:35 2016 New Revision: 294405 URL: https://svnweb.freebsd.org/changeset/base/294405 Log: MFV r294374: BIND 9.9.8-P3. Modified: stable/9/contrib/bind9/CHANGES stable/9/contrib/bind9/README stable/9/contrib/bind9/doc/arm/Bv9ARM.ch01.html

svn commit: r294376 - stable/9/contrib/bind9

2016-01-19 Thread Xin LI
Author: delphij Date: Wed Jan 20 07:33:45 2016 New Revision: 294376 URL: https://svnweb.freebsd.org/changeset/base/294376 Log: Mergeinfo fixup. Modified: Directory Properties: stable/9/contrib/bind9/ (props changed) ___

svn commit: r294287 - in stable/9: contrib/less usr.bin/less

2016-01-18 Thread Xin LI
Author: delphij Date: Mon Jan 18 19:27:24 2016 New Revision: 294287 URL: https://svnweb.freebsd.org/changeset/base/294287 Log: MFC r293190: MFV r293125: less v481. Relnotes: yes Added: stable/9/contrib/less/compose.uni - copied unchanged from r293190,

svn commit: r292320 - in stable/9/contrib/bind9: . doc/arm lib/dns lib/dns/include/dns lib/lwres/man

2015-12-16 Thread Xin LI
Author: delphij Date: Wed Dec 16 06:10:05 2015 New Revision: 292320 URL: https://svnweb.freebsd.org/changeset/base/292320 Log: MFV r292314: Update BIND to 9.9.8-P2. See release notes for notable changes: https://kb.isc.org/article/AA-01326 Note this is a direct commit to

svn commit: r290151 - stable/9/share/timedef

2015-10-29 Thread Xin LI
Author: delphij Date: Thu Oct 29 17:04:43 2015 New Revision: 290151 URL: https://svnweb.freebsd.org/changeset/base/290151 Log: MFC r289038,r289041: Add encoding for mime-types. Fix short month names and replace %b with %_m in date_fmt for Chinese locales. When using a Chinese

svn commit: r288511 - in stable: 10/usr.sbin/rpcbind 9/usr.sbin/rpcbind

2015-10-02 Thread Xin LI
Author: delphij Date: Fri Oct 2 16:36:16 2015 New Revision: 288511 URL: https://svnweb.freebsd.org/changeset/base/288511 Log: Fix a regression with SA-15:24 patch that prevented NIS from working. Modified: stable/9/usr.sbin/rpcbind/rpcb_svc_com.c Changes in other areas also in this

svn commit: r288384 - in stable: 10/usr.sbin/rpcbind 9/usr.sbin/rpcbind

2015-09-29 Thread Xin LI
Author: delphij Date: Tue Sep 29 18:06:27 2015 New Revision: 288384 URL: https://svnweb.freebsd.org/changeset/base/288384 Log: The Sun RPC framework uses a netbuf structure to represent the transport specific form of a universal transport address. The structure is expected to be opaque to

svn commit: r288206 - stable/9/usr.sbin/gstat

2015-09-24 Thread Xin LI
Author: delphij Date: Fri Sep 25 01:17:52 2015 New Revision: 288206 URL: https://svnweb.freebsd.org/changeset/base/288206 Log: MFC r287650: Use strlcpy() in favor of strncpy() as it's defined to have a nul character at the end of string buffer, and the code context do expects this to

svn commit: r287548 - stable/9/lib/libc/posix1e

2015-09-07 Thread Xin LI
Author: delphij Date: Tue Sep 8 01:46:52 2015 New Revision: 287548 URL: https://svnweb.freebsd.org/changeset/base/287548 Log: MFC r287093: Instead of doing an no-op (|= 0), actually clear the flags in acl_clear_flags_np. Reported by: Pascal Drecker Modified:

svn commit: r287447 - stable/9/usr.bin/bluetooth/btsockstat

2015-09-03 Thread Xin LI
Author: delphij Date: Fri Sep 4 00:42:05 2015 New Revision: 287447 URL: https://svnweb.freebsd.org/changeset/base/287447 Log: MFC r287345: Drop group privileges after opening the kvm descriptor, otherwise, the code would not drop privileges as expected. While there also add checks

svn commit: r287409 - in stable/9/contrib/bind9/lib/dns: . include/dst rdata/generic

2015-09-02 Thread Xin LI
Author: delphij Date: Wed Sep 2 20:06:46 2015 New Revision: 287409 URL: https://svnweb.freebsd.org/changeset/base/287409 Log: Fix remote denial of service vulnerability when parsing malformed key. Fix remote denial of service vulnerability caused by an incorrect boundary check in

svn commit: r287144 - in stable: 10/crypto/openssh 9/crypto/openssh

2015-08-25 Thread Xin LI
Author: delphij Date: Tue Aug 25 20:48:44 2015 New Revision: 287144 URL: https://svnweb.freebsd.org/changeset/base/287144 Log: MFC: Fix OpenSSH multiple vulnerabilities. Security: FreeBSD-SA-15:22.openssh Modified: stable/9/crypto/openssh/monitor.c

svn commit: r286936 - stable/9/usr.sbin/pkg

2015-08-19 Thread Xin LI
Author: delphij Date: Wed Aug 19 18:33:25 2015 New Revision: 286936 URL: https://svnweb.freebsd.org/changeset/base/286936 Log: Instant-MFC r286933: Issue warning and refuse to proceed further if the configured repository signature_type is unsupported by bootstrap pkg(7). Previously,

svn commit: r286900 - in stable: 10/contrib/expat/lib 9/contrib/expat/lib

2015-08-18 Thread Xin LI
Author: delphij Date: Tue Aug 18 19:30:05 2015 New Revision: 286900 URL: https://svnweb.freebsd.org/changeset/base/286900 Log: Fix multiple integer overflows in expat. Security: CVE-2015-1283 Security: FreeBSD-SA-15:20.expat Modified: stable/9/contrib/expat/lib/xmlparse.c

svn commit: r286387 - stable/9/etc

2015-08-06 Thread Xin LI
Author: delphij Date: Thu Aug 6 19:53:41 2015 New Revision: 286387 URL: https://svnweb.freebsd.org/changeset/base/286387 Log: MFC r286375: Remove INDEX-8 (and INDEX-7) as they are EoL'ed. Modified: stable/9/etc/portsnap.conf Directory Properties: stable/9/etc/ (props changed)

svn commit: r286349 - stable/9/sbin/routed

2015-08-05 Thread Xin LI
Author: delphij Date: Wed Aug 5 22:05:07 2015 New Revision: 286349 URL: https://svnweb.freebsd.org/changeset/base/286349 Log: Fix routed remote denial of service vulnerability. [SA-15:19] Modified: stable/9/sbin/routed/input.c Modified: stable/9/sbin/routed/input.c

svn commit: r285977 - in stable: 8/contrib/bind9/lib/dns 8/crypto/openssh 8/sys/netinet 9/contrib/bind9/lib/dns 9/crypto/openssh 9/sys/netinet

2015-07-28 Thread Xin LI
Author: delphij Date: Tue Jul 28 19:58:54 2015 New Revision: 285977 URL: https://svnweb.freebsd.org/changeset/base/285977 Log: Fix resource exhaustion in TCP reassembly. [SA-15:15] Fix OpenSSH multiple vulnerabilities. [SA-15:16] Fix BIND remote denial of service vulnerability.

svn commit: r285779 - in stable: 8/sys/netinet 9/sys/netinet

2015-07-21 Thread Xin LI
Author: delphij Date: Tue Jul 21 23:42:20 2015 New Revision: 285779 URL: https://svnweb.freebsd.org/changeset/base/285779 Log: Fix resource exhaustion due to sessions stuck in LAST_ACK state. Security: CVE-2015-5358 Security: SA-15:13.tcp Submitted by: Jonathan Looney (Juniper

svn commit: r285257 - in stable: 8/contrib/bind9/lib/dns 9/contrib/bind9/lib/dns

2015-07-07 Thread Xin LI
Author: delphij Date: Tue Jul 7 21:43:23 2015 New Revision: 285257 URL: https://svnweb.freebsd.org/changeset/base/285257 Log: Fix BIND resolver remote denial of service when validating. Security: CVE-2015-4620 Security: FreeBSD-SA-15:11.bind Modified:

svn commit: r284781 - in stable/9: contrib/file contrib/file/doc contrib/file/magic contrib/file/magic/Magdir contrib/file/python contrib/file/src contrib/file/tests lib/libmagic

2015-06-24 Thread Xin LI
Author: delphij Date: Wed Jun 24 23:04:07 2015 New Revision: 284781 URL: https://svnweb.freebsd.org/changeset/base/284781 Log: MFC r284237,r284277: file 5.23. Added: stable/9/contrib/file/magic/Magdir/cbor - copied unchanged from r284237, head/contrib/file/magic/Magdir/cbor

svn commit: r284525 - stable/9/lib/libc/locale

2015-06-17 Thread Xin LI
Author: delphij Date: Wed Jun 17 19:13:13 2015 New Revision: 284525 URL: https://svnweb.freebsd.org/changeset/base/284525 Log: MFC r264038 (theraven) Fix an issue where the locale and rune locale could become out of sync, causing mb* functions (and similar) to be called with the wrong

svn commit: r282871 - stable/9/usr.sbin/freebsd-update

2015-05-13 Thread Xin LI
Author: delphij Date: Wed May 13 22:36:52 2015 New Revision: 282871 URL: https://svnweb.freebsd.org/changeset/base/282871 Log: MFC r279571,281563 (allanjude): Add a new safetly belt to freebsd-update to prevent a user doing a minor update (-pX) while having an unfinished major upgrade

svn commit: r282053 - stable/9/usr.bin/gzip

2015-04-27 Thread Xin LI
...@eterna.com.au with unpack support written by -.An Xin LI Aq delp...@freebsd.org . +.An Xin LI Aq Mt delp...@freebsd.org . .Sh BUGS According to RFC 1952, the recorded file size is stored in a 32-bit integer, therefore, it can not represent files larger than 4GB. Modified: stable/9/usr.bin/gzip

svn commit: r281273 - in stable/9: contrib/bind9 contrib/bind9/bin/check contrib/bind9/bin/dig contrib/bind9/bin/dig/include/dig contrib/bind9/bin/dnssec contrib/bind9/bin/named contrib/bind9/bin/n...

2015-04-08 Thread Xin LI
Author: delphij Date: Wed Apr 8 19:49:38 2015 New Revision: 281273 URL: https://svnweb.freebsd.org/changeset/base/281273 Log: Update BIND to 9.9.7. This is a direct commit to stable/9 because BIND is no longer in -HEAD. Added: stable/9/contrib/bind9/doc/arm/Bv9ARM.ch11.html -

svn commit: r281231 - in stable: 8/contrib/ntp/ntpd 8/sys/netinet 8/sys/netinet6 9/contrib/ntp/ntpd 9/sys/netinet 9/sys/netinet6

2015-04-07 Thread Xin LI
Author: delphij Date: Tue Apr 7 20:20:44 2015 New Revision: 281231 URL: https://svnweb.freebsd.org/changeset/base/281231 Log: Improve patch for SA-15:04.igmp to solve a potential buffer overflow. Fix multiple vulnerabilities of ntp. [SA-15:07] Fix Denial of Service with IPv6 Router

svn commit: r280274 - in stable: 10/crypto/openssl/crypto/asn1 10/crypto/openssl/crypto/ec 10/crypto/openssl/crypto/x509 8/crypto/openssl/crypto/asn1 8/crypto/openssl/crypto/ec 8/crypto/openssl/cry...

2015-03-20 Thread Xin LI
Author: delphij Date: Fri Mar 20 07:11:20 2015 New Revision: 280274 URL: https://svnweb.freebsd.org/changeset/base/280274 Log: Fix issues with original SA-15:06.openssl commit: - Revert a portion of ASN1 change per suggested by OpenBSD and OpenSSL developers. The change was removed

svn commit: r280266 - in stable: 10/crypto/openssl/crypto/asn1 10/crypto/openssl/crypto/pkcs7 10/crypto/openssl/doc/crypto 10/crypto/openssl/ssl 10/secure/lib/libcrypto/man 8/crypto/openssl/crypto/...

2015-03-19 Thread Xin LI
Author: delphij Date: Thu Mar 19 17:40:43 2015 New Revision: 280266 URL: https://svnweb.freebsd.org/changeset/base/280266 Log: Fix multiple OpenSSL vulnerabilities. Security: FreeBSD-SA-15:06.openssl Security: CVE-2015-0209 Security: CVE-2015-0286 Security:

svn commit: r279263 - in stable: 10/sys/netinet 8/sys/netinet 9/sys/netinet

2015-02-24 Thread Xin LI
Author: delphij Date: Wed Feb 25 05:43:02 2015 New Revision: 279263 URL: https://svnweb.freebsd.org/changeset/base/279263 Log: Instant MFC: Fix integer overflow in IGMP protocol. Security: FreeBSD-SA-15:04.igmp Security: CVE-2015-1414 Found by: Mateusz Kocielski,

svn commit: r278972 - in stable/9/contrib/bind9: . lib/dns

2015-02-18 Thread Xin LI
Author: delphij Date: Wed Feb 18 22:20:19 2015 New Revision: 278972 URL: https://svnweb.freebsd.org/changeset/base/278972 Log: MFV r278971: Apply vendor fix for CVE-2015-1349. This is a direct commit to stable/9 because BIND is removed from HEAD. Modified:

svn commit: r278911 - stable/9/lib/libc/regex

2015-02-17 Thread Xin LI
Author: delphij Date: Tue Feb 17 19:14:41 2015 New Revision: 278911 URL: https://svnweb.freebsd.org/changeset/base/278911 Log: MFC r278739: Disallow pattern spaces which would cause intermediate calculations to overflow size_t. Obtained from:DragonFly

svn commit: r278176 - stable/9/usr.bin/grep

2015-02-03 Thread Xin LI
Author: delphij Date: Wed Feb 4 00:45:28 2015 New Revision: 278176 URL: https://svnweb.freebsd.org/changeset/base/278176 Log: MFC r277463: Fix xz handling for files larger than 32K. Submitted by: Stefan Ehmann shoesoft gmx net PR: bin/186861 Modified:

svn commit: r278178 - stable/9/cddl/contrib/opensolaris/lib/libzfs/common

2015-02-03 Thread Xin LI
Author: delphij Date: Wed Feb 4 00:52:26 2015 New Revision: 278178 URL: https://svnweb.freebsd.org/changeset/base/278178 Log: MFC r277433: MFV r277432: Plug various memory leaks in libzfs import implementation. Illumos issue: 5518 Memory leaks in libzfs import implementation

svn commit: r278106 - in stable: 10/sys/dev/vt 9/sys/dev/vt

2015-02-02 Thread Xin LI
Author: delphij Date: Mon Feb 2 18:48:49 2015 New Revision: 278106 URL: https://svnweb.freebsd.org/changeset/base/278106 Log: MFC r277806: Use unsigned int for index value. Without this change a local attacker could trigger a panic by tricking the kernel into accessing undefined

svn commit: r277807 - in stable: 10/sys/netinet 8/sys/netinet 9/sys/netinet

2015-01-27 Thread Xin LI
Author: delphij Date: Tue Jan 27 19:36:08 2015 New Revision: 277807 URL: https://svnweb.freebsd.org/changeset/base/277807 Log: Fix SCTP SCTP_SS_VALUE kernel memory corruption and disclosure vulnerability and SCTP stream reset vulnerability. Security: FreeBSD-SA-15:02.kmem Security:

svn commit: r276554 - stable/9/lib/libc/regex

2015-01-02 Thread Xin LI
Author: delphij Date: Fri Jan 2 18:51:47 2015 New Revision: 276554 URL: https://svnweb.freebsd.org/changeset/base/276554 Log: MFC r275930: Plug a memory leak. Obtained from:DragonFlyBSD (commit 5119ece) Modified: stable/9/lib/libc/regex/regcomp.c Directory Properties:

svn commit: r276416 - in stable/9: contrib/file contrib/file/Magdir contrib/file/doc contrib/file/m4 contrib/file/magic contrib/file/magic/Magdir contrib/file/python contrib/file/src contrib/file/t...

2014-12-30 Thread Xin LI
Author: delphij Date: Tue Dec 30 19:51:30 2014 New Revision: 276416 URL: https://svnweb.freebsd.org/changeset/base/276416 Log: MFC: file 5.21 Added: stable/9/contrib/file/config.guess - copied unchanged from r267897, head/contrib/file/config.guess stable/9/contrib/file/config.sub

svn commit: r276435 - stable/9/usr.bin/file

2014-12-30 Thread Xin LI
Author: delphij Date: Wed Dec 31 00:09:05 2014 New Revision: 276435 URL: https://svnweb.freebsd.org/changeset/base/276435 Log: MFC r267897: Update Makefile to reflect file update. Modified: stable/9/usr.bin/file/Makefile Directory Properties: stable/9/usr.bin/file/ (props changed)

svn commit: r276073 - in stable: 8/contrib/ntp/ntpd 8/contrib/ntp/util 9/contrib/ntp/ntpd 9/contrib/ntp/util

2014-12-22 Thread Xin LI
Author: delphij Date: Mon Dec 22 19:08:09 2014 New Revision: 276073 URL: https://svnweb.freebsd.org/changeset/base/276073 Log: MFC r276071: Fix multiple ntp vulnerabilities. Reviewed by: roberto (earlier revision), philip Security: CVE-2014-9293, CVE-2014-9294 Security:

svn commit: r275669 - in stable: 8/contrib/bind9 8/contrib/bind9/bin/named 8/contrib/bind9/lib/dns 8/contrib/bind9/lib/dns/include/dns 8/contrib/bind9/lib/export/isc 8/contrib/bind9/lib/isc 8/contr...

2014-12-10 Thread Xin LI
Author: delphij Date: Wed Dec 10 08:31:41 2014 New Revision: 275669 URL: https://svnweb.freebsd.org/changeset/base/275669 Log: Fix multiple vulnerabilities in file(1) and libmagic(3). Security: FreeBSD-SA-14:28.file Security: CVE-2014-3710, CVE-2014-8116, CVE-2014-8117 Fix

svn commit: r275627 - stable/9/lib/libc/gen

2014-12-08 Thread Xin LI
Author: delphij Date: Tue Dec 9 00:47:46 2014 New Revision: 275627 URL: https://svnweb.freebsd.org/changeset/base/275627 Log: MFC r275071: Reinstitate send() after syslogd restarts. In r228193 the test of CONNPRIV have been moved to before the _usleep and send in vsyslog(). When

svn commit: r273412 - in stable/9: sbin/routed sys/kern usr.sbin/rtsold

2014-10-21 Thread Xin LI
Author: delphij Date: Tue Oct 21 20:20:17 2014 New Revision: 273412 URL: https://svnweb.freebsd.org/changeset/base/273412 Log: Fix rtsold(8) remote buffer overflow vulnerability. [SA-14:20] Fix routed(8) remote denial of service vulnerability. [SA-14:21] Fix memory leak in sandboxed

svn commit: r273425 - stable/9/lib/libcrypt

2014-10-21 Thread Xin LI
Author: delphij Date: Tue Oct 21 21:09:54 2014 New Revision: 273425 URL: https://svnweb.freebsd.org/changeset/base/273425 Log: MFC r272830 (des): Change the hardcoded default back from SHA512 to DES. This will become EN-14:11.crypt. PR: 192277 Modified:

svn commit: r273427 - stable/9/usr.sbin/pw

2014-10-21 Thread Xin LI
Author: delphij Date: Tue Oct 21 21:11:25 2014 New Revision: 273427 URL: https://svnweb.freebsd.org/changeset/base/273427 Log: MFC r272833 (des): Two more places where login_setcryptfmt() defaults to MD5 were missed in r252688. Modified: stable/9/usr.sbin/pw/pw_user.c Directory

svn commit: r272426 - stable/9/sys/cddl/boot/zfs

2014-10-02 Thread Xin LI
Author: delphij Date: Thu Oct 2 17:42:02 2014 New Revision: 272426 URL: https://svnweb.freebsd.org/changeset/base/272426 Log: MFC r272389: Diff reduction with kernel code: instruct the compiler that the data of these types may be unaligned to their normal alignment and exercise

svn commit: r272439 - stable/9/usr.bin/at

2014-10-02 Thread Xin LI
Author: delphij Date: Thu Oct 2 18:32:17 2014 New Revision: 272439 URL: https://svnweb.freebsd.org/changeset/base/272439 Log: MFC r272288,272289: When setting environment variables in the atrun script, use the export foo=bar form instead of foo=bar; export foo since the former allows

svn commit: r271668 - in stable: 8/sys/netinet 9/sys/netinet

2014-09-16 Thread Xin LI
Author: delphij Date: Tue Sep 16 09:49:11 2014 New Revision: 271668 URL: http://svnweb.freebsd.org/changeset/base/271668 Log: Fix Denial of Service in TCP packet processing. Security: FreeBSD-SA-14:19.tcp Modified: stable/9/sys/netinet/tcp_input.c Changes in other areas also in

svn commit: r270816 - stable/9/sys/dev/hptnr

2014-08-29 Thread Xin LI
Author: delphij Date: Fri Aug 29 13:37:01 2014 New Revision: 270816 URL: http://svnweb.freebsd.org/changeset/base/270816 Log: MFC r270384: Update hptnr(4) driver to version 1.0.1 supplied by the vendor. v1.0.1 2014-8-19 * Do not retry the command and reset the disk when failed to

svn commit: r269221 - in stable: 8/libexec/save-entropy 9/libexec/save-entropy

2014-07-29 Thread Xin LI
Author: delphij Date: Tue Jul 29 06:00:48 2014 New Revision: 269221 URL: http://svnweb.freebsd.org/changeset/base/269221 Log: MFC r268979: Don't save entropy inside jails. As of r126744, we no longer feed the entropy device in jails upon start, and collecting them is no longer

svn commit: r268432 - in stable: 10/sys/kern 10/sys/netinet 8/sys/kern 8/sys/netinet 9/sys/kern 9/sys/netinet

2014-07-08 Thread Xin LI
Author: delphij Date: Tue Jul 8 21:54:50 2014 New Revision: 268432 URL: http://svnweb.freebsd.org/changeset/base/268432 Log: Fix kernel memory disclosure in control message and SCTP notifications. Security: FreeBSD-SA-14:17.kmem Security: CVE-2014-3952, CVE-2014-3953 Modified:

svn commit: r268101 - stable/9/sys/contrib/x86emu

2014-07-01 Thread Xin LI
Author: delphij Date: Tue Jul 1 16:00:48 2014 New Revision: 268101 URL: http://svnweb.freebsd.org/changeset/base/268101 Log: MFC r267372-267374: fix various misimplementation of instructions. Submitted by: Wolf Ramovsky wolf.ramovsky gmail.com Modified:

svn commit: r267458 - in stable/9/sys/dev: hpt27xx hptmv hptrr

2014-06-13 Thread Xin LI
Author: delphij Date: Sat Jun 14 00:54:57 2014 New Revision: 267458 URL: http://svnweb.freebsd.org/changeset/base/267458 Log: MFC r267368: Apply vendor fixes to the High Point drivers: - Don't call xpt_free_path() in os_query_remove_device() and always return TRUE. - Update

svn commit: r267379 - stable/9/lib/libc/gen

2014-06-11 Thread Xin LI
Author: delphij Date: Thu Jun 12 00:15:07 2014 New Revision: 267379 URL: http://svnweb.freebsd.org/changeset/base/267379 Log: Cumulative update to arc4random(3). MFC r227519, r227520, r238118, r241046: r227519 (das) Sync the style, comments, and variable names of arc4random.c

svn commit: r267139 - stable/9/sys/cddl/contrib/opensolaris/uts/common/fs/zfs

2014-06-05 Thread Xin LI
Author: delphij Date: Fri Jun 6 00:15:54 2014 New Revision: 267139 URL: http://svnweb.freebsd.org/changeset/base/267139 Log: MFC r266915: MFV 266913+266914: 3897 zfs filesystem and snapshot limits (fix leak) 4901 zfs filesystem/snapshot limit leaks Approved by: re (gjb) Modified:

svn commit: r267015 - in stable/9: contrib/openpam/lib/libpam sys/kern

2014-06-03 Thread Xin LI
Author: delphij Date: Tue Jun 3 19:02:33 2014 New Revision: 267015 URL: http://svnweb.freebsd.org/changeset/base/267015 Log: Fix ktrace kernel memory disclosure. [SA-14:12] Fix incorrect error handling in PAM policy parser. [SA-14:13] Approved by: re (glebius) Modified:

svn commit: r266818 - stable/9/secure/lib/libcrypt

2014-05-28 Thread Xin LI
Author: delphij Date: Wed May 28 19:05:46 2014 New Revision: 266818 URL: http://svnweb.freebsd.org/changeset/base/266818 Log: MFC r265995: Switch using the new $2b$ format by default, when bcrypt is used. Relnotes: default Blowfish crypt(3) format have been changed to $2b$.

svn commit: r266762 - in stable/9: . cddl/lib/libzfs

2014-05-27 Thread Xin LI
Author: delphij Date: Tue May 27 18:54:45 2014 New Revision: 266762 URL: http://svnweb.freebsd.org/changeset/base/266762 Log: MFC r266520: Explicitly link libzfs against libavl as it is done in OpenSolaris (4543:12bb2876a62e). Without this, some third party applications may break

svn commit: r266458 - stable/9/contrib/ntp/ntpd

2014-05-19 Thread Xin LI
Author: delphij Date: Tue May 20 00:57:28 2014 New Revision: 266458 URL: http://svnweb.freebsd.org/changeset/base/266458 Log: MFC r265465: Don't reply monlist request when it's not enabled. Modified: stable/9/contrib/ntp/ntpd/ntp_request.c Directory Properties: stable/9/contrib/ntp/

svn commit: r265748 - in stable/9/cddl/contrib/opensolaris/cmd: zdb zfs zpool

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 07:34:38 2014 New Revision: 265748 URL: http://svnweb.freebsd.org/changeset/base/265748 Log: MFC r263459 (MFV 263436-263438): 3947 zpool(1M) references nonexistent zfs-features(5) 4540 zpool(1M) man page doesn't describe readonly property 3948 zfs

svn commit: r265749 - in stable/9/cddl/contrib/opensolaris: cmd/zpool lib/libzfs/common

2014-05-09 Thread Xin LI
, Martin Matuska m...@freebsd.org. +.\ Copyright (c) 2013-2014, Xin Li delp...@freebsd.org. .\ All Rights Reserved. .\ .\ The contents of this file are subject to the terms of the @@ -25,7 +26,7 @@ .\ .\ $FreeBSD$ .\ -.Dd March 20, 2014 +.Dd March 28, 2014 .Dt ZPOOL 8 .Os .Sh NAME @@ -70,6 +71,8

svn commit: r265750 - stable/9/contrib/netcat

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 07:38:22 2014 New Revision: 265750 URL: http://svnweb.freebsd.org/changeset/base/265750 Log: MFC: nc(1) from OpenBSD 5.5. Modified: stable/9/contrib/netcat/FREEBSD-vendor stable/9/contrib/netcat/atomicio.c stable/9/contrib/netcat/nc.1

svn commit: r265751 - in stable/9: cddl/contrib/opensolaris/cmd/zdb cddl/contrib/opensolaris/lib/libzpool/common cddl/contrib/opensolaris/lib/libzpool/common/sys sys/cddl/contrib/opensolaris/uts/co...

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 07:54:59 2014 New Revision: 265751 URL: http://svnweb.freebsd.org/changeset/base/265751 Log: MFC r264669: MFV r264666: 4374 dn_free_ranges should use range_tree_t Modified: stable/9/cddl/contrib/opensolaris/cmd/zdb/zdb.c

svn commit: r265752 - in stable/9/sys/cddl/contrib/opensolaris/uts/common/fs/zfs: . sys

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 08:02:52 2014 New Revision: 265752 URL: http://svnweb.freebsd.org/changeset/base/265752 Log: MFC r264671: MFV r264668: 4754 io issued to near-full luns even after setting noalloc threshold 4755 mg_alloc_failures is no longer needed Modified:

svn commit: r265753 - stable/9/usr.sbin/portsnap/portsnap

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 08:07:05 2014 New Revision: 265753 URL: http://svnweb.freebsd.org/changeset/base/265753 Log: MFC r264740: Use case insensitive match in portsnap. PR: bin/186510 Submitted by: olli Modified: stable/9/usr.sbin/portsnap/portsnap/portsnap.sh

svn commit: r265754 - in stable/9: cddl/contrib/opensolaris/cmd/zfs cddl/contrib/opensolaris/cmd/zpool cddl/contrib/opensolaris/lib/libzfs/common sys/cddl/contrib/opensolaris/common/zfs sys/cddl/co...

2014-05-09 Thread Xin LI
...@freebsd.org .\ Copyright (c) 2014, Xin LI delp...@freebsd.org .\ .\ $FreeBSD$ .\ -.Dd March 20, 2014 +.Dd April 23, 2014 .Dt ZFS 8 .Os .Sh NAME @@ -536,6 +536,13 @@ if the snapshot has been marked for defe .Qq Nm Cm destroy -d command. Otherwise, the property is .Cm off . +.It Sy

svn commit: r265755 - in stable/9/sys/cddl/contrib/opensolaris: common/avl uts/common/sys

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 08:13:11 2014 New Revision: 265755 URL: http://svnweb.freebsd.org/changeset/base/265755 Log: MFC r264836: MFV r264830: 4745 fix AVL code misspellings Modified: stable/9/sys/cddl/contrib/opensolaris/common/avl/avl.c

svn commit: r265756 - stable/9/sys/cddl/contrib/opensolaris/uts/common/fs/zfs

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 08:15:35 2014 New Revision: 265756 URL: http://svnweb.freebsd.org/changeset/base/265756 Log: MFC r265458: Import George Wilson's change for Illumos #4730: 4730 metaslab group taskq should be destroyed in metaslab_group_destroy() Reviewed

svn commit: r265757 - stable/9/lib/libmagic

2014-05-09 Thread Xin LI
Author: delphij Date: Fri May 9 08:18:57 2014 New Revision: 265757 URL: http://svnweb.freebsd.org/changeset/base/265757 Log: MFC r265464: Sort .ALLSRC before concatenating files together. This makes sure that the file are always built the same. (Note that Header and Localstuff

svn commit: r265123 - in stable: 8/sys/netinet 8/sys/sys 9/sys/netinet 9/sys/sys

2014-04-29 Thread Xin LI
Author: delphij Date: Wed Apr 30 04:04:20 2014 New Revision: 265123 URL: http://svnweb.freebsd.org/changeset/base/265123 Log: Fix TCP reassembly vulnerability. Patch done by:glebius Security: FreeBSD-SA-14:08.tcp Security: CVE-2014-3000 Modified:

svn commit: r264624 - in stable: 8/crypto/openssl/crypto/rand 9/crypto/openssl/crypto/rand

2014-04-17 Thread Xin LI
Author: delphij Date: Thu Apr 17 20:09:41 2014 New Revision: 264624 URL: http://svnweb.freebsd.org/changeset/base/264624 Log: Cherry-pick OpenSSL changeset 5be1ae2: Author: Dr. Stephen Henson st...@openssl.org Treat a zero length passed to ssleay_rand_add a no op: the existing

svn commit: r264579 - stable/9/bin/dd

2014-04-16 Thread Xin LI
Author: delphij Date: Thu Apr 17 00:34:49 2014 New Revision: 264579 URL: http://svnweb.freebsd.org/changeset/base/264579 Log: MFC all recent changes on -HEAD to dd(1). Modified: stable/9/bin/dd/args.c stable/9/bin/dd/conv_tab.c stable/9/bin/dd/dd.1 stable/9/bin/dd/dd.c

svn commit: r264285 - in stable: 8/crypto/openssl/crypto/bn 8/crypto/openssl/crypto/ec 8/sys/fs/nfsserver 9/crypto/openssl/crypto/bn 9/crypto/openssl/crypto/ec 9/sys/fs/nfsserver

2014-04-08 Thread Xin LI
Author: delphij Date: Tue Apr 8 23:16:19 2014 New Revision: 264285 URL: http://svnweb.freebsd.org/changeset/base/264285 Log: Fix NFS deadlock vulnerability. [SA-14:05] Fix ECDSA Cache Side-channel Attack in OpenSSL. [SA-14:06] Modified: stable/9/crypto/openssl/crypto/bn/bn.h

svn commit: r264061 - stable/9/cddl/contrib/opensolaris/cmd/zpool

2014-04-02 Thread Xin LI
Author: delphij Date: Thu Apr 3 01:02:14 2014 New Revision: 264061 URL: http://svnweb.freebsd.org/changeset/base/264061 Log: MFC r263385: Remove unused option -r from zpool. Submitted by: Richard Yao ryao gentoo org Modified:

  1   2   3   >