Stable release: HardenedBSD-stable 10-STABLE v46.19

HardenedBSD-10-STABLE-v46.19 - https://github.com/HardenedBSD/hardenedBSD-stable/releases/tag/HardenedB...

Warning: this is a security update!

Highlights:

  • Advanced ifunc resolver in rtld (ebcf883abaa4a5407d9321c90e77b62d5400239e)
  • Updated ntpd to 4.2.8p2 (ae8e146bd5a44ecee88074684cfb450384368980) [FreeBSD-SA-Candidate]
  • Possible UFS related kernel panic fix (f1841547a520610c8f48c2c0b473b55dc84e1714)

Installer images:
http://installer.hardenedbsd.org/pub/HardenedBSD/releases/amd64/amd64/IS...

CHECKSUM.SHA512:

SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-bootonly.iso) = 98bfe0c145d04e8476a6af8639c8a1324c96572d4fc3739708e45e2bbab210a79c0bb766171034bba946b53db32782edf5f81d78a7f1d71603d6270117590027
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-disc1.iso) = 6c1672403a04dc819b45be7846332767266c1e565db14fb5d82e26792ccec4024f0348c71242464e18c3b4011fd235dfdc686ba8e342f2edea9d1b097167ba97
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-memstick.img) = 7297be987017198e761f85f43677677826b8828fce6bc8b7c233f6ec40abf84f5d23fdfe63c0c2be42d7017a8c8417286b793fdd865df68dbe769f31433a354c
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-mini-memstick.img) = ee63073bef4d3e4e8f2b86c8649b403eafaf7341432966fa97c76ad01544bff5e4819be84befa51ce7dd3f3c8da9c8192b6a7883cf3113f2306ddba7e4182811
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-bootonly.iso) = e776686a78c765125bb3cd2adb7cefbec1e529ba4ceca31a19809ccb7d1ca9c6076fe8f404f1eed7a7d616abd1219ea7d22356f8eb30432074ca414e5d5f05d9
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-disc1.iso) = 5cba03d06f4c7d67cac958843c9a7026dfdf4b498ad658c1bf112a9dca04b45fa16d89c1be0c8fd316ac2b37a05e58498b9459cde81144a2942497edccf43852
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-memstick.img) = 117e6ebee28e9660dc5461f5b5dd7ef940ac09539dd2e2f7f8da11f821c7f4db3a9f3fa356a655ca7fff192dad4d6e39137e26cb79f6737ff31afd6106cf65f1
SHA512 (HardenedBSD-10-STABLE-v46.19-amd64-uefi-mini-memstick.img) = 258221b9771875eb49e7ac997d1d3924023976fae5f9247659d474eba69acca5cae29bc2b2ef6894494760d322287976b79e09746e718869f2cfb74ec174b3ce

CHECKSUM.SHA512.asc:

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEu1M4jTvZiSgVy54wgZsRom/9GI0FAlg2IwMACgkQgZsRom/9
GI3yoA/+NIY/HrcYpsGI23u0F4OnWV9AHRIEsaRdkq6vFAfXlaX0Idlh710ZQEgw
TbTCEGWFTGNBnr004JmPp9DNvUfSdjgK3I1LGV9TZvEqzv5kybY6cmZLYjzyw7nx
sreCTKlviJePbRViAjWPbPNH8a9G8nQModDeD+AoOzYx1j/S16uilsMETQDTV+lL
ROW3C+ia2XyK/wTW3AVoC1AjoeRvDV73bOP8Qfs8RLqyqmAZu2ii15BRNkMMuACz
XwxSQ6Dg22f8U9vTSinnr9RmPfT9LyFChwiE7CokKqJG5ROL/esbWaRBSch9UmQS
nulrrbBAy2LhoUzSlG/100SsWBsn8B3ZMhpBpJgINGhU5gBLCSW4PWLvE5yo38eE
6qKWpjOq3YXUvON0wvO4sjTw/QOoIhMB2sTp8H35tv/sDBZpd0sSr4yMTCKWD9MK
Vm8WlxH8fXlDkCPG7ugdqYL45A8zkiaXYO6jHuGiNlvYznaxytY1O6zjXSB5c5FA
IJ/t1br0q3f844mELDHuMkQOg3UqWi+Vr/x0oni9bKCdcp89U4xaDCyB6Jb3jo/X
6bYnXG1FTuzijxE9nfs/kFw1tZhoSJmB6t87gkiIgvFR/u7U4m5PfhoV59sOkrj8
OSZ3kzInbxEqNfglcWfi9UVaJJwQOkkDWfE5Z4GBHFOX3yrOSqo=
=5c4N
-----END PGP SIGNATURE-----


Changelog:

Oliver Pinter + (16):

  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
  • Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master


asomers (2):

  • MFC r307752
  • MFC r307584 (partially)


avg (8):

  • MFC r308040,308479: nap time between pats is forced to be at most half of the timeout
  • MFC r307195: convert iicsmb to use iicbus_transfer for all operations
  • MFC r308101: hwpmc: fix a race between amd_stop_pmc and amd_intr
  • MFC r308218: Add support for microcode update on newer AMD CPUs (10h+)
  • MFC r308247: MFV r308222: 6051 lzc_receive: allow the caller to read the begin record
  • Revert r308753: some unrelated changes were included into the commit
  • MFC r308040,308479: nap time between pats is forced to be at most half of the timeout
  • MFC r308089: zfsbootcfg: a simple tool to set next boot (one time) options for zfsboot


delphij (1):

  • MFC r308957: MFV r308954:


emaste (2):

  • MFC r282824: crunchide: remove EOL whitespace
  • MFC r306740, r307150: groff: use changelog date in man pages


hrs (2):

  • MFC r308347:
  • MFC r308348:


jhb (1):

  • MFC 306999: Add a missing word.


jilles (2):

  • MFC r306585: swapon(8): Update to reality: swapoff ignores -L and the late option in fstab.
  • MFC r307755: swapoff: Remove only late devices with -aL.


kib (6):

  • MFC r308538: Increase the max allowed size of the microcode update blob for x86.
  • MFC r308642: Initialize reserved bytes in struct mq_attr.
  • MFC r308687: Update hint to utilize user variable.
  • MFC r308688: Assert that there is no unresolved symbols during rtld linking.
  • MFC r308733: Move the fast fault path into the separate function.
  • MFC r308689: Pass CPUID[1] %edx (cpu_feature), %ecx (cpu_feature2) and CPUID[7].%ebx (cpu_stdext_feature), %ecx (cpu_stdext_feature2) to the ifunc resolvers on x86.


mav (2):

  • MFC r308464, r308471: Add some device IDs found in my new laptop.
  • MFC r308425: Add support for EIIOE flag in Additional Element Status.


mckusick (1):

  • MFC r307978: Bug 180894 reports that rm -rf on a directory causes kernel panic and reboot. Return EINVAL rather than panic for low directory link count.