Page MenuHomeFreeBSD
Feed Advanced Search

Mar 7 2018

gordon committed rD51467: Add the actual patches to the doc repo. This would help people interested.
Add the actual patches to the doc repo. This would help people interested
Mar 7 2018, 2:57 PM
gordon committed rD51466: NTP patches are large. Exempt myself from the limit to commit them..
NTP patches are large. Exempt myself from the limit to commit them.
Mar 7 2018, 2:56 PM
gordon committed rD51465: Add actual patches to the doc repo. This would probably help..
Add actual patches to the doc repo. This would probably help.
Mar 7 2018, 2:55 PM
gordon committed rD51464: Switch order of the SA and EN in the xml to sort properly..
Switch order of the SA and EN in the xml to sort properly.
Mar 7 2018, 7:08 AM
gordon committed rD51463: Add SA-18:01, SA-18:02, EN-18:01, EN-18:02..
Add SA-18:01, SA-18:02, EN-18:01, EN-18:02.
Mar 7 2018, 6:46 AM
gordon committed rS330569: Update file(1) to new version with security update. [EN-18:02.file].
Update file(1) to new version with security update. [EN-18:02.file]
Mar 7 2018, 6:05 AM
gordon committed rS330568: Update timezone database information. [EN-18:01.tzdata].
Update timezone database information. [EN-18:01.tzdata]
Mar 7 2018, 6:01 AM
gordon committed rS330567: Fix multiple vulnerabilities in ntp. [SA-18:02.ntp].
Fix multiple vulnerabilities in ntp. [SA-18:02.ntp]
Mar 7 2018, 5:59 AM
gordon committed rS330566: Fix ipsec validation and use-after-free. [SA-18:01.ipsec].
Fix ipsec validation and use-after-free. [SA-18:01.ipsec]
Mar 7 2018, 5:53 AM
gordon committed rS330565: Port r329561 to stable/10. There were structural changes preventing MFC..
Port r329561 to stable/10. There were structural changes preventing MFC.
Mar 7 2018, 5:48 AM

Mar 5 2018

gordon added reviewers for D14500: Implement getrandom(2) and getentropy(3): cperciva, jmg.

Adding cperciva and jmg who may be able to help provide some opinions about how they think this should go.

Mar 5 2018, 8:51 PM

Feb 6 2018

gordon accepted D14211: devel/p4 devel/p4api: cache distfiles in LOCAL.

Okay, based on that, looks good to me.

Feb 6 2018, 12:31 AM

Feb 5 2018

gordon added a comment to D14211: devel/p4 devel/p4api: cache distfiles in LOCAL.

Would it be better off to just not do checksumming for this and use the source as is?

Feb 5 2018, 9:41 PM

Feb 4 2018

gordon committed rP460954: MFH: r460953.
MFH: r460953
Feb 4 2018, 11:37 PM
gordon committed rP460953: Fixup include for p4 related ports now that devel/p4 is using source..
Fixup include for p4 related ports now that devel/p4 is using source.
Feb 4 2018, 11:35 PM

Jan 16 2018

gordon added a comment to D13925: random: Add CCP random source.
In D13925#292062, @cem wrote:

Conrad, thanks for the details. I also looked at the code in the other review and it looks good. I’d expect whitened output from the ctr-aes drbg to measure ~6.5 bits when put through the sp800-90b tool. That’s roughly what you get out of 1000000 samples from RDRND on Intel.

FWIW, these processors also have RDRAND. I don't know if the RDRAND implementation is related to the CCP device TRNG or not.

I obtained some sample output from the CTR-AES DRBG via kgdb and /dev/mem:

Jan 16 2018, 5:17 AM
gordon added a reviewer for D13925: random: Add CCP random source: badfilemagic_gmail.com.

This is fine (obviously missing the actual implementation). Adding Dean to the reviewers, he has history in doing assessments of HW TRNG and might be a good collaborator to look at the quality of the bits coming from ccp(4).

Jan 16 2018, 2:00 AM

Dec 21 2017

gordon committed rP456884: MFH: r456883.
MFH: r456883
Dec 21 2017, 4:09 AM
gordon committed rP456883: Update devel/p4d and devel/p4p to 2016.1/1598719 due to micropatching..
Update devel/p4d and devel/p4p to 2016.1/1598719 due to micropatching.
Dec 21 2017, 4:07 AM

Dec 17 2017

gordon committed rD51316: Update so_public_key with new key..
Update so_public_key with new key.
Dec 17 2017, 5:16 AM
gordon committed rD51315: Update PGP key for security-officer..
Update PGP key for security-officer.
Dec 17 2017, 4:41 AM

Dec 15 2017

gordon accepted D13459: kern.ipc.{msqids,semsegs,sema} sysctls for FreeBSD32..

Looks okay to me but I'm probably not the best person to judge. If anyone else would like to weigh in. Feel free.

Dec 15 2017, 6:15 AM

Dec 9 2017

gordon closed D13418: Update for OpenSSL CVE-2017-3737 and CVE-2017-3738..
Dec 9 2017, 4:18 AM
gordon committed rD51269: Add FreeBSD-SA-17:12.openssl..
Add FreeBSD-SA-17:12.openssl.
Dec 9 2017, 4:04 AM
gordon committed rS326723: Fix error state handling.
Fix error state handling
Dec 9 2017, 3:45 AM
gordon committed rS326722: Fix multiple OpenSSL vulnerabilities..
Fix multiple OpenSSL vulnerabilities.
Dec 9 2017, 3:44 AM
gordon committed rS326721: Fix error state handling..
Fix error state handling.
Dec 9 2017, 3:42 AM

Dec 8 2017

gordon committed rD51265: Correct spelling: exceprt to excerpt..
Correct spelling: exceprt to excerpt.
Dec 8 2017, 7:28 AM
gordon added a member for secteam: emaste.
Dec 8 2017, 5:37 AM
gordon added reviewers for D13418: Update for OpenSSL CVE-2017-3737 and CVE-2017-3738.: secteam, jkim.

Can you please review?

Dec 8 2017, 4:26 AM
gordon created D13418: Update for OpenSSL CVE-2017-3737 and CVE-2017-3738..
Dec 8 2017, 4:26 AM

Dec 6 2017

gordon committed rD51261: Update website to make 11.0 unsupported now that it is EoL..
Update website to make 11.0 unsupported now that it is EoL.
Dec 6 2017, 11:13 PM
gordon closed D13392: Documentation EoL for 11.0-RELEASE..
Dec 6 2017, 11:13 PM
gordon committed rS326639: I don't need the sizelimit exception anymore..
I don't need the sizelimit exception anymore.
Dec 6 2017, 10:03 PM
gordon added a comment to D13392: Documentation EoL for 11.0-RELEASE..
In D13392#279901, @gjb wrote:

shouldn't we try to renumber the rel0.current/rel1.current stuff ? I forgot how we did that in the past though so I can be mistaken :)

Generally, yes, but it tends to be a bit more complicated than what Gordon has proposed here.

Dec 6 2017, 7:18 PM
gordon updated the diff for D13392: Documentation EoL for 11.0-RELEASE..

Accommodate r51259.

Dec 6 2017, 5:54 PM
gordon added a reviewer for D13392: Documentation EoL for 11.0-RELEASE.: secteam.

I should have added secteam as well. Sorry about that.

Dec 6 2017, 5:43 PM
gordon added a reviewer for D13392: Documentation EoL for 11.0-RELEASE.: doceng.

Adding doceng

Dec 6 2017, 5:47 AM
gordon created D13392: Documentation EoL for 11.0-RELEASE..
Dec 6 2017, 5:46 AM

Dec 5 2017

gordon added a comment to D12405: Diff showing stock tcpdump 4.9.2 vs FreeBSD 4.9.2.

Is this ready to commit now?

Dec 5 2017, 9:11 PM

Nov 21 2017

gordon committed rD51209: Update SA-17:08 and SA-17:10 to properly give credit to Ilja van Sprundel..
Update SA-17:08 and SA-17:10 to properly give credit to Ilja van Sprundel.
Nov 21 2017, 3:48 AM

Nov 17 2017

gordon committed rS325942: Correct grammar nit..
Correct grammar nit.
Nov 17 2017, 3:46 PM

Nov 15 2017

gordon committed rS325879: Correct patch level..
Correct patch level.
Nov 15 2017, 11:29 PM
gordon committed rD51201: Add SA-17:08, SA-17:09, SA-17:10..
Add SA-17:08, SA-17:09, SA-17:10.
Nov 15 2017, 11:09 PM
gordon committed rS325878: Properly bzero kldstat structure to prevent information leak. [SA-17:10].
Properly bzero kldstat structure to prevent information leak. [SA-17:10]
Nov 15 2017, 10:51 PM
gordon committed rS325877: Properly bzero kldstat structure to prevent information leak. [SA-17:10].
Properly bzero kldstat structure to prevent information leak. [SA-17:10]
Nov 15 2017, 10:51 PM
gordon committed rS325876: Properly bzero kldstat structure to prevent information leak. [SA-17:10].
Properly bzero kldstat structure to prevent information leak. [SA-17:10]
Nov 15 2017, 10:50 PM
gordon committed rS325875: Properly bzero kldstat structure to prevent information leak. [SA-17:10].
Properly bzero kldstat structure to prevent information leak. [SA-17:10]
Nov 15 2017, 10:50 PM
gordon committed rS325874: Fix namespace issue in POSIX shm implementation for jails. [SA-17:09].
Fix namespace issue in POSIX shm implementation for jails. [SA-17:09]
Nov 15 2017, 10:46 PM
gordon committed rS325873: Fix namespace issue in POSIX shm implementation for jails. [SA-17:09].
Fix namespace issue in POSIX shm implementation for jails. [SA-17:09]
Nov 15 2017, 10:45 PM
gordon committed rS325871: Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08].
Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08]
Nov 15 2017, 10:41 PM
gordon committed rS325870: Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08].
Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08]
Nov 15 2017, 10:40 PM
gordon committed rS325869: Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08].
Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08]
Nov 15 2017, 10:40 PM
gordon committed rS325868: Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08].
Fix kernel data leak via ptrace(PT_LWPINFO). [SA-17:08]
Nov 15 2017, 10:40 PM
gordon committed rS325867: MFC r325865.
MFC r325865
Nov 15 2017, 10:35 PM
gordon committed rS325866: MFC r325865.
MFC r325865
Nov 15 2017, 10:34 PM
gordon committed rS325865: Properly bzero kldstat structure to prevent kernel information leak..
Properly bzero kldstat structure to prevent kernel information leak.
Nov 15 2017, 10:30 PM

Nov 7 2017

gordon committed rD51184: Update the secteam with a few additional changes..
Update the secteam with a few additional changes.
Nov 7 2017, 3:51 PM

Nov 2 2017

gordon committed rD51167: Add EN-17:09..
Add EN-17:09.
Nov 2 2017, 3:56 PM
gordon committed rS325325: Update timezone database information. [EN-17:09].
Update timezone database information. [EN-17:09]
Nov 2 2017, 3:40 PM
gordon committed rS325324: Update timezone database information. [EN-17:09].
Update timezone database information. [EN-17:09]
Nov 2 2017, 3:40 PM
gordon committed rS325323: Update timezone database information. [EN-17:09].
Update timezone database information. [EN-17:09]
Nov 2 2017, 3:39 PM
gordon committed rS325322: Update timezone database information. [EN-17:09].
Update timezone database information. [EN-17:09]
Nov 2 2017, 3:38 PM

Nov 1 2017

gordon added a comment to D12899: Prepare to add more information about our triaging of items..

Generally looks good. Mostly grammar nits and some clarification needed.

Nov 1 2017, 8:18 PM

Oct 20 2017

gordon committed rD51139: Set 11.0 end of life date..
Set 11.0 end of life date.
Oct 20 2017, 7:26 PM

Oct 19 2017

gordon committed rD51136: Update SA-17:07 with patches for 10.x..
Update SA-17:07 with patches for 10.x.
Oct 19 2017, 3:28 AM
gordon committed rS324741: Fix WPA2 protocol vulnerability. [SA-17:07].
Fix WPA2 protocol vulnerability. [SA-17:07]
Oct 19 2017, 3:20 AM
gordon committed rS324740: Fix WPA2 protocol vulnerability. [SA-17:07].
Fix WPA2 protocol vulnerability. [SA-17:07]
Oct 19 2017, 3:20 AM
gordon committed rS324739: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..
Update wpa_supplicant/hostapd for 2017-01 vulnerability release.
Oct 19 2017, 3:18 AM
gordon closed D12724: Backport wpa fixes to stable/10..
Oct 19 2017, 3:18 AM

Oct 18 2017

gordon added a reviewer for D12724: Backport wpa fixes to stable/10.: secteam.
Oct 18 2017, 9:50 PM

Oct 17 2017

gordon committed rS324708: Correct copy-paste. 11.1 is p2, not p13..
Correct copy-paste. 11.1 is p2, not p13.
Oct 17 2017, 9:20 PM
gordon committed rD51128: Add SA-17:07..
Add SA-17:07.
Oct 17 2017, 6:11 PM
gordon committed rS324699: Fix WPA2 protocol vulnerability. [SA-17:07].
Fix WPA2 protocol vulnerability. [SA-17:07]
Oct 17 2017, 5:57 PM
gordon committed rS324698: Fix WPA2 protocol vulnerability. [SA-17:07].
Fix WPA2 protocol vulnerability. [SA-17:07]
Oct 17 2017, 5:56 PM
gordon committed rS324697: MFC r324696: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..
MFC r324696: Update wpa_supplicant/hostapd for 2017-01 vulnerability release.
Oct 17 2017, 5:30 PM
gordon committed rS324696: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..
Update wpa_supplicant/hostapd for 2017-01 vulnerability release.
Oct 17 2017, 5:22 PM
gordon closed D12693: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..
Oct 17 2017, 5:22 PM
gordon added a comment to D12693: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..

I believe this is the expected set of patches. I noticed one minor difference between the Debian patch set I inspected and this (tk_to_set vs tk_already_set) which is probably due to targeting different versions?

Oct 17 2017, 2:20 PM
gordon added reviewers for D12693: Update wpa_supplicant/hostapd for 2017-01 vulnerability release.: jhb, secteam.
Oct 17 2017, 6:04 AM
gordon created D12693: Update wpa_supplicant/hostapd for 2017-01 vulnerability release..
Oct 17 2017, 6:04 AM

Oct 10 2017

gordon committed rP451655: Update b2 to latest from Backblaze..
Update b2 to latest from Backblaze.
Oct 10 2017, 5:23 AM
gordon closed D12139: Update devel/b2 to 0.7.2..
Oct 10 2017, 5:23 AM

Oct 5 2017

gordon committed rS324322: MFC r323709:.
MFC r323709:
Oct 5 2017, 5:02 PM

Sep 18 2017

gordon committed rS323709: Revert tcpdump to using the source manpage instead of having a copy here..
Revert tcpdump to using the source manpage instead of having a copy here.
Sep 18 2017, 4:42 PM
gordon closed D12403: Instead of keeping a one off copy of the generated man page, follow the same pattern as the file(1) utility and generate the man page from the sources as part of the build..
Sep 18 2017, 4:42 PM
gordon created D12405: Diff showing stock tcpdump 4.9.2 vs FreeBSD 4.9.2.
Sep 18 2017, 5:55 AM
gordon created D12404: Update tcpdump to 4.9.2..
Sep 18 2017, 5:40 AM
gordon created D12403: Instead of keeping a one off copy of the generated man page, follow the same pattern as the file(1) utility and generate the man page from the sources as part of the build..
Sep 18 2017, 5:28 AM
gordon committed rS323697: Tag tcpdump-4.9.2..
Tag tcpdump-4.9.2.
Sep 18 2017, 4:13 AM
gordon committed rS323696: Vendor import of tcpdump 4.9.2..
Vendor import of tcpdump 4.9.2.
Sep 18 2017, 4:11 AM
gordon committed rS323695: Add myself to import new tcpdump image..
Add myself to import new tcpdump image.
Sep 18 2017, 4:10 AM

Sep 17 2017

gordon committed rS323683: MFV r323678: file 5.32.
MFV r323678: file 5.32
Sep 17 2017, 9:30 PM
gordon closed D12400: Update to file 5.32.

Landed as r323683

Sep 17 2017, 9:28 PM
gordon created D12400: Update to file 5.32.
Sep 17 2017, 5:31 PM
gordon committed rS323679: Tag file 5.32..
Tag file 5.32.
Sep 17 2017, 3:58 PM
gordon committed rS323678: Vendor import of file 5.32..
Vendor import of file 5.32.
Sep 17 2017, 3:57 PM

Sep 15 2017

gordon committed rS323550: Deorbit catman. The tradeoff of disk for performance has long since tipped.
Deorbit catman. The tradeoff of disk for performance has long since tipped
Sep 15 2017, 8:52 PM
gordon closed D12317: Deorbit catman. It's useless on modern hardware..

Committed as r323550.

Sep 15 2017, 8:49 PM

Sep 11 2017

gordon created D12317: Deorbit catman. It's useless on modern hardware..
Sep 11 2017, 5:09 AM