Add missing comma in Credits line.
Add SA-25:10 and related patches.
Add UPDATING entries and bump version.
Add a fix to scrub unsolicited NS RRSets to prevent cache poisoning.
Add UPDATING entries and bump version.
Add a fix to scrub unsolicited NS RRSets to prevent cache poisoning.
Add UPDATING entry and bump version number.
Mitigate YXDOMAIN and nodata non-referral answer poisoning.
Mitigate YXDOMAIN and nodata non-referral answer poisoning.
Mitigate YXDOMAIN and nodata non-referral answer poisoning.
Mitigate YXDOMAIN and nodata non-referral answer poisoning.
Mitigate YXDOMAIN and nodata non-referral answer poisoning.
Add backup pkgbase signing key held by security-officer.
Add backup pkgbase signing key held by security-officer.
gordon retitled
D53879: Add backup pkgbase signing key held by security-officer from
Add security-officer pkgbase keys to build to
Add backup pkgbase signing key held by security-officer.
libc: Add "Z" as TZ designator for strptime.
libc: Add "Z" as TZ designator for strptime.
libc: Add "Z" as TZ designator for strptime.
libc: Add "Z" as TZ designator for strptime.
website: Move 14.2 to unsupported on security page.
Add EN-25:18 and SA-25:08.
freebsd-update: Library ordering
freebsd-update: Library ordering
Add UPDATING entries and bump version.
Add UPDATING entries and bump version.
freebsd-update: Library ordering
Fix multiple security issues in OpenSSL.
Add UPDATING entries and bump version.
Fix multiple security issues in OpenSSL.
Fix multiple security issues in OpenSSL.
Fix multiple security issues in OpenSSL.
Fix multiple security issues in OpenSSL.
Seems fine to me. I haven't tested at all, just reviewed the change on Phab. Everything here makes as much sense as I can make out of it (take that for what you will :-)
Looking at what should be in the legacy provider, I fell down this rabbit hole by looking at a completely stock build of 3.5.4-dev on my Mac (I should probably check on a FreeBSD system and see if it is any different, but that would require a small amount of effort and I'm about to go to a dinner) and see this list as the primary objects that end up in the legacy provider:
How did you come up with these changes? What was the methodology that got this changeset?
Correct release patch information.
Add EN-25:15 through EN-25:17.
arm64: prevent panic when using syscall mux + large arg call (mmap)
arm64: prevent panic when using syscall mux + large arg call (mmap)
Add UPDATING entries and bump version.
vfs_syscalls.c: Fix handling of offset args for copy_file_range
arm64: prevent panic when using syscall mux + large arg call (mmap)
Add UPDATING entries and bump version.
Add UPDATING entries and bump version.
bnxt: Fix BASE-T, 40G AOC, 1G-CX, autoneg and unknown media lists
Add EN-25:12 through EN-25:14 and SA-25:07.
libarchive: merge from vendor branch
net80211: fix TKIP trailer trimming w/ no rx parameters given
Add a new sysctl in order to diffrentiate UEFI architectures
libarchive: merge from vendor branch
Add UPDATING entries and bump version.
route: fix `route -n monitor` when its output is redirected
libarchive: merge from vendor branch
Add UPDATING entries and bump version.
route: fix `route -n monitor` when its output is redirected
Add UPDATING entries and bump version.
Add EN-25:09 through EN-25:11 and SA-25:06.
ena: Bump driver version to v2.8.1
ena: Fix misconfiguration when requesting regular LLQ
Add UPDATING entries and bump version.
ena: Bump driver version to v2.8.1
Fix Use-after-free in multi-threaded xz decoder.
ena: Fix misconfiguration when requesting regular LLQ
Fix corruption in ZFS replication streams from encrypted datasets.
libc: allow __cxa_atexit handlers to be added during __cxa_finalize
Add UPDATING entries and bump version.
Fix Use-after-free in multi-threaded xz decoder.
Fix corruption in ZFS replication streams from encrypted datasets.
libc: allow __cxa_atexit handlers to be added during __cxa_finalize
Add UPDATING entries and bump version.
Fix corruption in ZFS replication streams from encrypted datasets.
website: Remove EoL'd 14.1-RELEASE
Extend lifetime of my key.
I’m not entirely sure what kind of approval from secteam is being sought. If someone in core would like to help me understand what kind of review is expected, I’d be happy to undertake it.
Add EN-25:04 through EN-25:08.
ssh: Bump VersionAddendum for CVE fixes
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
ssh: Bump VersionAddendum for CVE fixes
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
Add updating entries and bump version.
ssh: Bump VersionAddendum for CVE fixes
Add UPDATING entries and bump version.
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
Add UPDATING entries and bump version
As long as it doesn't end up as a build product, makes sense to me. Want to update the review with a new patch and we'll go from there?
Move this to the proper name.