Extend lifetime of my key.
I’m not entirely sure what kind of approval from secteam is being sought. If someone in core would like to help me understand what kind of review is expected, I’d be happy to undertake it.
Add EN-25:04 through EN-25:08.
ssh: Bump VersionAddendum for CVE fixes
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
ssh: Bump VersionAddendum for CVE fixes
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
Add updating entries and bump version.
ssh: Bump VersionAddendum for CVE fixes
Add UPDATING entries and bump version.
ssh: Fix cases where error codes were not correctly set
ssh: Don't reply to PING in preauth phase or during KEX
Add UPDATING entries and bump version
As long as it doesn't end up as a build product, makes sense to me. Want to update the review with a new patch and we'll go from there?
Move this to the proper name.
Add EN-25:01 through EN-25:03 and SA-25:01 through SA-25:04.
Update expiration date on existing keys for security-officer.
Correct CVE typo for SA-24:17.bhyve.
Add EN-24:17 and SA-24:17 through SA-24:19.
Correct the reference to FreeBSD-SA-24:16.libnv.
allanjude is the core team liaison for secteam.
security: Fixup incorrect pathes in EN-24:16.pf.
Add EN-24:16, SA-24:15, and SA-24:16. Update SA-24:05 and SA-24:09.
libnv: correct the calculation of the structure's size
bhyve: improve input validation in pci_xhci
Add UPDATING entries and bump revision.
bhyve: improve input validation in pci_xhci
libnv: correct the calculation of the structure's size
Add UPDATING entries and bump revision.
bhyve: improve input validation in pci_xhci
libnv: correct the calculation of the structure's size
Add UPDATING entries and bump revision.
bhyve: improve input validation in pci_xhci
libnv: correct the calculation of the structure's size
Add UPDATING entries and bump revision.
website/security: Reverse sort release table.
openssl: Remove the specific version numbers from the instructions.
openssl: Update upgrade instructions.
Assuming this is a straight import, LGTM.
openssl: Remove fips module from base system.
Add advisories to relavent toml files.
Add EN-24:15 and SA-24:09 through SA-24:14.
calendar: don't setlogin(2) in the -a user handlers
openssl: Import OpenSSL 3.0.15.
openssl: Avoid type errors in EAI-related name check logic.
openssl: Bring over fix for CVE-2024-6119 from vendor/openssl-3.0.
Avoid type errors in EAI-related name check logic.
openssl: Remove fips module from base system.
release: Redirect etcupdate logfile to /dev/null.
release: Redirect etcupdate logfile to /dev/null.
release: Redirect etcupdate logfile to /dev/null.
Adding all of releng instead of just cperciva
Note this is a direct commit to releng/13.4, although it might be better to do a corresponding change to main (slightly different patch needed) -> stable/13 -> releng/13.4.
SA-24:07: Correct patch paths.
website: Add EN-24:14 and SA-24:05 through SA-24:08.
Not sure who else to get this reviewed by, but we should stop shipping fips.so.
website: Retire last remaining bits of 13.2.
Add EN-24:10 through EN-24:13.
killpg(): more carefully avoid LoR
ldns: Ignore commented-out lines in resolv.conf.
ldns: Ignore commented-out lines in resolv.conf.
Add UPDATING entries and bump the branch version.
Add UPDATING entries and bump the branch version.
Destroy ARC buffer in case of fill error
Merge commit 382f70a877f0 from llvm-project (by Louis Dionne):
Add UPDATING entries and bump the branch version.
Seeing how CIDR has been a thing for around 30 years, erroring without a netmask is the appropriate action here.
Migrate from printb to print_bits for locally defined bit fields.
Move print_bits to ifconfig.c and make available to other src files.
Address comments from emaste.
Update secteam composition.
Unify arc_prune_async() code, fix excessive ARC pruning
Add UPDATING entries and bump the branch version.
Add EN-24:05 through EN-24:08, SA-24:03.
Merge commit f800c1f3b207 from llvm-project (by Arthur Eubanks):
if_wg: use proper barriers around pkt->p_state
Add UPDATING entries and bump the branch version.
unbound: Vendor import 1.19.1
if_wg: use proper barriers around pkt->p_state
kern: fix panic with disabled ttys