New release notes:
fixes of vm_object_*() and contigmalloc(), em(4) 82541ER and 82546GB support, ixgb(4) added, sk(4) jumbo frame handling fix, net.inet.tcp.insecure_rst sysctl, ips(4) added, mpt(4) FC929X support, and linux_base-8 used by default. Approved by: re (implicitly)
<para>A bug in &man.mmap.2; that pages marked as <literal>PROT_NONE</literal>
may become readable under certain circumstances, has been fixed.</para>
+ <para>Bugs in <function>vm_object_madvise()</function>,
+ <function>vm_object_sync()</function>, and
+ <function>contigmalloc()</function>
+ functions in the &os; virtual memory subsystem have been fixed.
+ The bugs in <function>vm_object_madvise()</function>
+ and <function>vm_object_sync()</function> could
+ cause memory corruption in a variety of contexts, and
+ one in <function>contigmalloc()</function>
+ could cause a system panic.</para>
<sect3 id="proc">
<sect3 id="net-if">
<title>Network Interface Support</title>
+ <para>The &man.em.4; driver now supports 82541ER and 82546GB
+ dual port PCI Express adapter.</para>
+ <para>The &man.ixgb.4; driver, which supports PCI Gigabit
+ Ethernet adapters based on the Intel 82597EX Ethernet
+ controller chips, has been added.</para>
<para>The &man.ng.hub.4; Netgraph node type, which supports
a simple packet distribution that acts like an Ethernet hub
has been added.</para>
+ <para>A bug of jumbo frame handling in the &man.sk.4; driver
+ has been fixed.</para>
<para>The &man.vr.4; driver now supports &man.polling.4;.</para>
<para>The per-interface &man.polling.4; support has been
<para>&man.ipfw.4; now supports lookup tables. This feature is
useful for handling large sparse address sets.</para>
+ <para>The <literal>RST</literal>
+ handling of the &os; TCP stack has been improved
+ to make reset attacks as difficult as possible while
+ maintaining compatibility with the widest range of TCP stacks.
+ The algorithm is as follows. For connections in the
+ <literal>ESTABLISHED</literal>
+ state, only resets with sequence numbers exactly matching
+ <varname>last_ack_sent</varname> will cause a reset,
+ all other segments will
+ be silently dropped. For connections in all other states,
+ a reset anywhere in the window will cause the connection
+ to be reset. All other segments will be silently dropped.
+ You can still disable this and use the conventional behavior
+ by setting a new sysctl <varname>net.inet.tcp.insecure_rst</varname>
+ to <literal>1</literal>.</para>
<title>Disks and Storage</title>
<para></para>
+ <para>The &man.ips.4; driver, which supports IBM/Adaptec ServeRAID controller
+ has been added.</para>
+ <para>The &man.mpt.4; driver now supports LSI Logic FC929X
+ Dual 2Gb/s Fibre Channel card.</para>
<para>The &man.cron.8 daemon now accepts two new options,
<option>-j</option> and <option>-J</option>, to enable
- time jitter for jobs to run as unpriviliged users and the
+ time jitter for jobs to run as unprivileged users and the
superuser, respectively. Time jitter means that &man.cron.8
will sleep for a small random period of time in the specified
range before executing a job. This feature is intended to
<para>A bug in &man.rarpd.8; that prevents it from working properly
when a interface has more than one IP address has been fixed.</para>
+ <para>&man.syslogd.8; now supports <literal>LOG_NTP</literal>
+ facility.</para>
<para>The supported release of <application>GNOME</application>
has been updated from 2.6 to 2.8.2.
The list of changes for each component can be found at
- <a href="http://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00026.html">
- http://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00026.html</a></para>
+ <ulink url="http://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00026.html">
+ http://mail.gnome.org/archives/gnome-announce-list/2004-December/msg00026.html</ulink>.</para>
<para>The supported release of <application>KDE</application>
has been updated from 3.2.2 to 3.3.2.</para>
+ <para>The supported userland package for Linux binary compatibility
+ has been updated from <filename role="package">linux_base-6</filename>
+ (based on Red Hat Linux 7.1)
+ to <filename role="package">linux_base-8</filename>
+ (based on Red Hat Linux 8.0).</para>