Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 3 Mar 2014 23:30:54 +0000 (UTC)
From:      Xin LI <delphij@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-10@freebsd.org
Subject:   svn commit: r262720 - stable/10
Message-ID:  <201403032330.s23NUsZL077099@svn.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: delphij
Date: Mon Mar  3 23:30:54 2014
New Revision: 262720
URL: http://svnweb.freebsd.org/changeset/base/262720

Log:
  (not quite, due to date difference) MFC r262719:
  
  Document the fact that OpenSSH default configuration requires Capsicum
  capability mode support in kernel, which have been worked around later
  but it's still recommended to have it enabled.
  
  Reported by:	many

Modified:
  stable/10/UPDATING
Directory Properties:
  stable/10/   (props changed)

Modified: stable/10/UPDATING
==============================================================================
--- stable/10/UPDATING	Mon Mar  3 23:26:48 2014	(r262719)
+++ stable/10/UPDATING	Mon Mar  3 23:30:54 2014	(r262720)
@@ -17,6 +17,16 @@ stable/10, and then rebuild without this
 older version of current is a bit fragile.
 
 
+20140303:
+	OpenSSH will now ignore errors caused by kernel lacking of Capsicum
+	capability mode support.  Please note that enabling the feature in
+	kernel is still highly recommended.
+
+20140227:
+	OpenSSH is now built with sandbox support, and will use sandbox as
+	the default privilege separation method.  This requires Capsicum
+	capability mode support in kernel.
+
 20140216:
 	The nve(4) driver for NVIDIA nForce MCP Ethernet adapters has
 	been deprecated and will not be part of FreeBSD 11.0 and later



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201403032330.s23NUsZL077099>