HardenedBSD-10-STABLE-v46.1

@opntr opntr released this May 23, 2016 · 4601 commits to hardened/10-stable/master since this release

This release fixes CVE-1541 and CVE-2015-2304 in libarchive, a lot of Coverity warnings / programing errors and an overflow in amd64's sysarch system call (00696f0, eac2aab, bd784f7).

Bernard Spil (1):
HBSD: contrib/libarchive: Import CVE-2016-1541 fix

Oliver Pinter (1):
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master

Oliver Pinter + (11):
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master
Merge branch 'freebsd/10-stable/master' into hardened/10-stable/master

asomers (1):
MFC r298420, r298439, r298644

bdrewery (4):
MFC r297947:
Allow MK_ overrides.
Bump version for r300233
Follow-up r300233: Don't override MK_* from env as head does.

dchagin (1):
MFC r299249:

emaste (2):
MFC r294935 (kan): Make .debug file for libgcc_s.so.1 more useful.
MFC r292000: Remove historical GNUC test

glebius (2):
Use unsigned version of min() when handling arguments of SETFKEY ioctl.
Validate that user supplied control message length is not negative.

kib (6):
MFC r299408: Style: wrap long lines.
MFC r299412: Add vfs_hash_ref(9) function, which finds a vnode by the hash value and returns it referenced.
MFC r299413: Use vfs_hash_ref(9) to eliminate LK_EXCLOTHER kludge.
HBSD MFC: Use unsigned type for the loop index to make overflow checks effective.
HBSD MFC: Check for overflow and return EINVAL if detected. Backport this and r300305 to i386.
MFC r300305, r300332: Check for overflow and return EINVAL if detected. Use unsigned index.

mav (2):
MFC r298983: Add some device IDs from Intel Sunrise Point chipsets.
MFC 103 ntb(4) patches by cem@ up to r295487.

mm (1):
Backport security fix for absolute path traversal vulnerability in bsdcpio.

ngie (5):
MFC r299654:
MFC r299655:
MFC r299659:
MFC r299712,r299759,r299760,r299761,r299762:
MFC r299710,r299711,r299763,r299783,r299811:

pfg (1):
MFC r299089: fsck_msdosfs: Adjust a check.

rmacklem (3):
MFC: r299201 Give mountd -S priority over outstanding RPC requests when suspending the nfsd.
MFC: r299226 Don't increment srvrpccnt[] for the NFSv4.1 operations.
MFC: r299242 Make "-S" a default option for mountd.

truckman (32):
MFC r299524
MFC r299525
MFC r290903, r299573
MFC r299577, r299578, r299589
MFC r299579
MFC r299580
MFC r299581
MFC r299585
MFC r299591
MFC r299592
MFC r299593
MFC r299865
MFC 299866
MFC r299867
MFC r299868
MFC r299869
MFC r299873
MFC r299879, r299880
MFC r299893
MFC r299894
MFC r299897
MFC r299922
MFC r299926
MFC r299948
MFC r299952
MFC r299953
MFC r299971
MFC r299986
MFC r299988
MFC r299991
MFC r300002
MFC r300005