Index: stable/5/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml =================================================================== --- stable/5/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml (revision 171595) +++ stable/5/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml (revision 171596) @@ -1,377 +1,377 @@ &os;/&arch; &release.current; Release Notes The &os; Project $FreeBSD$ 2000 2001 2002 2003 2004 2005 2006 2007 The &os; Documentation Project &tm-attrib.freebsd; &tm-attrib.ibm; &tm-attrib.ieee; &tm-attrib.intel; &tm-attrib.sparc; &tm-attrib.general; The release notes for &os; &release.current; contain a summary of the changes made to the &os; base system since &release.prev;. This document lists applicable security advisories that were issued since the last release, as well as significant changes to the &os; kernel and userland. Some brief remarks on upgrading are also presented. Introduction This document contains the release notes for &os; &release.current; on the &arch.print; hardware platform. It describes recently added, changed, or deleted features of &os;. It also provides some notes on upgrading from previous versions of &os;. The &release.type; distribution to which these release notes apply represents a point along the &release.branch; development branch after &release.prev;. Note that no further, formal releases on the &release.branch; branch are planned at this time. Information regarding pre-built, binary &release.type; distributions along this branch can be found at . ]]> This distribution of &os; &release.current; is a &release.type; distribution. It can be found at or any of its mirrors. More information on obtaining this (or other) &release.type; distributions of &os; can be found in the Obtaining &os; appendix to the &os; Handbook. ]]> All users are encouraged to consult the release errata before installing &os;. The errata document is updated with late-breaking information discovered late in the release cycle or after the release. Typically, it contains information on known bugs, security advisories, and corrections to documentation. An up-to-date copy of the errata for &os; &release.current; can be found on the &os; Web site. What's New This section describes the most user-visible new or changed features in &os; since &release.prev;. Typical release note items document recent security advisories issued after &release.prev;, new drivers or hardware support, new commands or options, major bug fixes, or contributed software upgrades. They may also list changes to major ports/packages or release engineering practices. Clearly the release notes cannot list every single change made to &os; between releases; this document focuses primarily on security advisories, user-visible changes, and major architectural improvements. Security Advisories A bug in &man.ypserv.8;, which effectively disabled the /var/yp/securenets access control mechanism, has been corrected. More details are available in security advisory FreeBSD-SA-06:15.ypserv. A bug in the smbfs file system, which could allow an attacker to escape out of &man.chroot.2 environments on an smbfs mounted filesystem, has been fixed. For more details, see security advisory FreeBSD-SA-06:16.smbfs. A potential denial of service problem in &man.sendmail.8; caused by excessive recursion which leads to stack exhaustion when attempting delivery of a malformed MIME message, has been fixed. For more details, see security advisory FreeBSD-SA-06:17.sendmail. A potential buffer overflow condition in &man.sppp.4; has been corrected. For more details, see security advisory FreeBSD-SA-06:18.ppp. An OpenSSL bug related to validation of PKCS#1 v1.5 signatures has been fixed. For more details, see security advisory FreeBSD-SA-06:19.openssl. A potential denial of service attack against &man.named.8; has been fixed. For more details, see security advisory FreeBSD-SA-06:20.bind. Several programming errors have been fixed in &man.gzip.1;. They could have the effect of causing a crash or an infinite loop when decompressing files. More information can be found in security advisory FreeBSD-SA-06:21.gzip. Several vulnerabilities have been fixed in OpenSSH. More details can be found in security advisory FreeBSD-SA-06:22.openssh. Multiple errors in the OpenSSL &man.crypto.3; library have been fixed. Potential effects are varied, and are documented in more detail in security advisory FreeBSD-SA-06:23.openssl. A bug that could allow users in the operator group to read parts of kernel memory has been corrected. For more details, consult security advisory FreeBSD-SA-06:25.kmem. A bug in &man.gtar.1; has been fixed. Under certain circumstances, this bug could allow an attacker to overwrite files with the permissions of a user running &man.gtar.1;. More details on the exact impact of the bug, as well as workaround and patch information, can be found in security advisory FreeBSD-SA-06:26.gtar. A bug in the jail startup script that could permit privilege escalation via a symlink attack has been fixed. More information is available in FreeBSD-SA-07:01.jail. Two remote denials of service in BIND (one involving DNSSEC and one involving recursive DNS queries) have been fixed. For more information, see security advisory FreeBSD-SA-07:02.bind. Processing of IPv6 type 0 Routing Headers is now controlled by the net.inet6.ip6.rthdr0_allowed sysctl variable, which defaults to 0 (off). For more information, see security advisory FreeBSD-SA-07:03.ipv6. Problems with &man.libarchive.3; and &man.tar.1; handling corrupted &man.tar.5; archive files have been fixed. More details can be found in security advisory FreeBSD-SA-07:05.libarchive. Kernel Changes Boot Loader Changes Hardware Support Multimedia Support Network Interface Support Network Protocols Multiple copies of a packet received via different &man.bpf.4; listeners now all have identical timestamps. The sysctl variables net.inet.ip.portrange.reservedhigh and net.inet.ip.portrange.reservedlow can be used with IPv6 now. Disks and Storage File Systems Contributed Software Userland Changes <filename>/etc/rc.d</filename> Scripts The sendmail script can be instructed not to rebuild the aliases database if it is missing or older than the aliases file. If desired, set the new rc.conf option sendmail_rebuild_aliases to "NO" to turn off that functionality. Contributed Software BIND has been updated from 9.3.1 - to 9.3.4. + to 9.3.4-p1. netcat has been updated from the version in a 4 February 2005 OpenBSD snapshot to the version included in OpenBSD 3.9. sendmail has been updated from 8.13.6 to 8.14.1. The timezone database has been updated from the tzdata2006g release to the tzdata2006n release. Ports/Packages Collection Infrastructure Release Engineering and Integration The supported version of the GNOME desktop environment (x11/gnome2) has been updated from 2.12.3 to 2.16.1. The supported version of the KDE desktop environment (x11/kde3) has been updated from 3.5.1 to 3.5.3. The supported Linux emulation now uses the libraries in the emulators/linux_base-fc4 package. Documentation Upgrading from previous releases of &os; If you're upgrading from a previous release of &os;, you generally will have three options: Using the binary upgrade option of &man.sysinstall.8;. This option is perhaps the quickest, although it presumes that your installation of &os; uses no special compilation options. Performing a complete reinstall of &os;. Technically, this is not an upgrading method, and in any case is usually less convenient than a binary upgrade, in that it requires you to manually backup and restore the contents of /etc. However, it may be useful in cases where you want (or need) to change the partitioning of your disks. From source code in /usr/src. This route is more flexible, but requires more disk space, time, and technical expertise. More information can be found in the Using make world section of the FreeBSD Handbook. Upgrading from very old versions of &os; may be problematic; in cases like this, it is usually more effective to perform a binary upgrade or a complete reinstall. Please read the INSTALL.TXT file for more information, preferably before beginning an upgrade. If you are upgrading from source, please be sure to read /usr/src/UPDATING as well. Finally, if you want to use one of various means to track the -STABLE or -CURRENT branches of &os;, please be sure to consult the -CURRENT vs. -STABLE section of the FreeBSD Handbook. Upgrading &os; should, of course, only be attempted after backing up all data and configuration files. Index: stable/6/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml =================================================================== --- stable/6/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml (revision 171595) +++ stable/6/release/doc/en_US.ISO8859-1/relnotes/common/new.sgml (revision 171596) @@ -1,414 +1,414 @@ &os;/&arch; &release.current; Release Notes The &os; Project $FreeBSD$ 2000 2001 2002 2003 2004 2005 2006 2007 The &os; Documentation Project &tm-attrib.freebsd; &tm-attrib.ibm; &tm-attrib.ieee; &tm-attrib.intel; &tm-attrib.sparc; &tm-attrib.general; The release notes for &os; &release.current; contain a summary of the changes made to the &os; base system on the &release.branch; development line. This document lists applicable security advisories that were issued since the last release, as well as significant changes to the &os; kernel and userland. Some brief remarks on upgrading are also presented. Introduction This document contains the release notes for &os; &release.current; on the &arch.print; hardware platform. It describes recently added, changed, or deleted features of &os;. It also provides some notes on upgrading from previous versions of &os;. The &release.type; distribution to which these release notes apply represents the latest point along the &release.branch; development branch since &release.branch; was created. Information regarding pre-built, binary &release.type; distributions along this branch can be found at . ]]> The &release.type; distribution to which these release notes apply represents a point along the &release.branch; development branch between &release.prev; and the future &release.next;. Information regarding pre-built, binary &release.type; distributions along this branch can be found at . ]]> This distribution of &os; &release.current; is a &release.type; distribution. It can be found at or any of its mirrors. More information on obtaining this (or other) &release.type; distributions of &os; can be found in the Obtaining &os; appendix to the &os; Handbook. ]]> All users are encouraged to consult the release errata before installing &os;. The errata document is updated with late-breaking information discovered late in the release cycle or after the release. Typically, it contains information on known bugs, security advisories, and corrections to documentation. An up-to-date copy of the errata for &os; &release.current; can be found on the &os; Web site. What's New This section describes the most user-visible new or changed features in &os; since &release.prev;. Typical release note items document recent security advisories issued after &release.prev;, new drivers or hardware support, new commands or options, major bug fixes, or contributed software upgrades. They may also list changes to major ports/packages or release engineering practices. Clearly the release notes cannot list every single change made to &os; between releases; this document focuses primarily on security advisories, user-visible changes, and major architectural improvements. Security Advisories Two remote denials of service in BIND (one involving DNSSEC and one involving recursive DNS queries) have been fixed. For more information, see security advisory FreeBSD-SA-07:02.bind. Processing of IPv6 type 0 Routing Headers is now controlled by the net.inet6.ip6.rthdr0_allowed sysctl variable, which defaults to 0 (off). For more information, see security advisory FreeBSD-SA-07:03.ipv6. Problems with &man.libarchive.3; and &man.tar.1; handling corrupted &man.tar.5; archive files have been fixed. More details can be found in security advisory FreeBSD-SA-07:05.libarchive. Kernel Changes &man.acpi.4; now has support for the HPET time counter. Support for Message Signaled Interrupts (MSI) and Extended Message Signaled Interrupts (MSI-X) has been added to the kernel's PCI support code. Boot Loader Changes Hardware Support An &man.acpi.dock.4; driver has been added to provide support for controlling laptop docking station functions via ACPI. Multimedia Support The &man.snd.envy24.4; driver has been added to support the Envy24 series of audio chips. The &man.snd.envy24ht.4; driver has been added to support the VIA Envy24HT series of audio chips. The &man.snd.hda.4; driver has been added. It supports devices that conform to revision 1.0 of the Intel High Definition Audio specification. The &man.snd.spicds.4; driver has been added to support I2S SPI audio codec chips. Network Interface Support The &man.ath.4; driver has been updated to HAL version 0.9.20.3. The &man.axe.4; driver now supports &man.altq.4;. The &man.cxgb.4; driver has been added. It provides support for 10 Gigabit Ethernet adapters based on the Chelsio T3 and T3B chipsets. The &man.edsc.4; driver, which provides Ethernet discard network interfaces, has been added. The &man.msk.4; driver has been added. It supports network interfaces using the Marvell/SysKonnect Yukon II Gigabit Ethernet controller. The &man.mxge.4; driver, which supports Myricom Myri10GE 10 Gigabit Ethernet adapters, has been added. For more details, see &man.mxge.4;. The &man.npe.4; driver, which supports the Intel XScale Network Processing Engine, has been added. The &man.vge.4; driver now supports &man.altq.4;. The 802.11 protocol stack now has support for 900 MHz cards, as well as quarter- and half-channel support for 802.11a. Network Protocols The &man.if.bridge.4; driver now supports RSTP, the Rapid Spanning Tree Protocol (802.1w). The &man.lagg.4; driver, ported from OpenBSD and NetBSD, has been added to support a variety of protocols and algorithms for link aggregation, failover, and fault tolerance. A new &man.ng.deflate.4; NetGraph node type has been added. It implements Deflate PPP compression. A new &man.ng.pred1.4; NetGraph node type has been added to implement Predictor-1 PPP compression. A bug which prevented &os; &release.prev; from running IPv6 correctly over &man.gif.4; tunnels has been fixed. The net.link.tap.up_on_open sysctl variable has been added to the &man.tap.4; driver. If enabled, new tap devices will marked up upon creation. Disks and Storage The &man.mpt.4; driver has been updated to support various new features such as RAID volume and RAID member state/settings reporting, periodic volume re-synchronization status reporting, and sysctl variables for volume re-synchronization rate, volume member write cache status, and volume transaction queue depth. The &man.mpt.4; driver now supports SAS HBA (partially), 64-bit PCI, and large data transfer. The scsi_sg driver, which emulates a significant subset of the Linux SCSI SG passthrough device API, has been added. It is intended to allow programs running under Linux emulation (as well as native &os; applications) to access the /dev/sg* devices supported by Linux. The &man.twa.4; driver has been updated to the 3.60.03.006 release on the 3ware Web site. It now supports AMCC's 3ware 9650 series of SATA controllers. File Systems The unionfs file system has been re-implemented. This version solves many crashing and locking issues compared to the previous implementation. It also adds new transparent and masquerade modes for automatically creating files in the upper file system layer of unions. More information can be found in the &man.mount.unionfs.8; manual page. Userland Changes A bug in &man.freebsd-update.8;, which caused it not to update SMP kernels correctly, has been fixed. The &man.fdisk.8; program now supports a flag to print the slice table in fdisk configuration format. The &man.ftpd.8; utility now has support for RFC2389 (FEAT) and rudimentary support for RFC2640 (UTF8). The RFC2640 support is optional and can be enabled using the new flag. More information can be found in the &man.ftpd.8; manual page. The &man.rpc.lockd.8; and &man.rpc.statd.8; programs now accept options to indicate which port they should bind to. The &man.pw.8; program now supports a option to set the permissions of a user's newly created home directory. The &man.top.1; program now supports a flag to display the &man.jail.8; ID for each process. The &man.touch.1; utility now supports a flag that allows the access and modification times of a file be adjusted by a specified value. The &man.wpa.passphrase.8; utility has been added. It generates a 256-bit pre-shared WPA key from an ASCII passphrase. <filename>/etc/rc.d</filename> Scripts The sendmail script can be instructed not to rebuild the aliases database if it is missing or older than the aliases file. If desired, set the new rc.conf option sendmail_rebuild_aliases to "NO" to turn off that functionality. Contributed Software BIND has been updated from 9.3.3 - to 9.3.4. + to 9.3.4-p1. BZIP2 has been updated from 1.0.3 to 1.0.4. GNU Diffutils has been updated from 2.7 to 2.8.7. The GNU version of gzip has been replaced with a modified version of gzip ported from NetBSD. less has been updated from v381 to v406. ncurses has been updated from 5.2-20020615 to 5.6-20061217. ncurses now also has wide character support. netcat has been updated from the version in a 4 February 2005 OpenBSD snapshot to the version included in OpenBSD 4.1. GNU Readline library has been updated from 5.0 to 5.2 patch 2. sendmail has been updated from 8.13.8 to 8.14.1. Ports/Packages Collection Infrastructure Release Engineering and Integration The supported version of the GNOME desktop environment (x11/gnome2) has been updated from 2.16.1 to 2.18.0. The supported version of the KDE desktop environment (x11/kde3) has been updated from 3.5.4 to 3.5.6. The supported version of the &xorg; windowing system (x11/xorg) has been updated from 6.9.0 to 7.2.0. The default value of X11BASE has been changed from /usr/X11R6 to /usr/local, the default value of LOCALBASE. Documentation Upgrading from previous releases of &os; Source upgrades to &os; &release.current; are only supported from &os; 5.3-RELEASE or later. Users of older systems wanting to upgrade &release.current; will need to update to &os; 5.3 or newer first, then to &os; &release.current;. Upgrading &os; should, of course, only be attempted after backing up all data and configuration files.