svn commit: r262720 - stable/10

Xin LI delphij at FreeBSD.org
Mon Mar 3 23:30:54 UTC 2014


Author: delphij
Date: Mon Mar  3 23:30:54 2014
New Revision: 262720
URL: http://svnweb.freebsd.org/changeset/base/262720

Log:
  (not quite, due to date difference) MFC r262719:
  
  Document the fact that OpenSSH default configuration requires Capsicum
  capability mode support in kernel, which have been worked around later
  but it's still recommended to have it enabled.
  
  Reported by:	many

Modified:
  stable/10/UPDATING
Directory Properties:
  stable/10/   (props changed)

Modified: stable/10/UPDATING
==============================================================================
--- stable/10/UPDATING	Mon Mar  3 23:26:48 2014	(r262719)
+++ stable/10/UPDATING	Mon Mar  3 23:30:54 2014	(r262720)
@@ -17,6 +17,16 @@ stable/10, and then rebuild without this
 older version of current is a bit fragile.
 
 
+20140303:
+	OpenSSH will now ignore errors caused by kernel lacking of Capsicum
+	capability mode support.  Please note that enabling the feature in
+	kernel is still highly recommended.
+
+20140227:
+	OpenSSH is now built with sandbox support, and will use sandbox as
+	the default privilege separation method.  This requires Capsicum
+	capability mode support in kernel.
+
 20140216:
 	The nve(4) driver for NVIDIA nForce MCP Ethernet adapters has
 	been deprecated and will not be part of FreeBSD 11.0 and later


More information about the svn-src-all mailing list