[ANNOUNCE] WOLK v4.4s FINAL - Server Edition
Marc-Christian Petersen <[email protected]>
| Newsgroups | gmane.linux.wolk.devel |
|---|---|
| Organization | Working Overloaded Linux Kernel |
| Message-ID | <200306071159.48383.m.c.p__22151.7200036489$1059547931@wolk-project.de> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi all,
so here we go, FINAL v4.4. This is the 4th maintenance update for WOLK4.0.
Many security issues have been fixed!
NOTE: Linux is going to annoy me more and more. I think I can say that Linux
is not an Operating System but anything else. I guess Linux needs more
_programmers_, not just only guys who are "coding".
I even don't know if I continue WOLK with the effort and time I did in
the past. I don't see a point in doing so. Maybe I will contribute and
help the Debian/BSD project. We'll see ... So far, have fun with 4.4s.
Changelog from v4.3s -> v4.4s
- -----------------------------
o added: High Performance Packet Classification (nf-hipac) v0.8 rev2
o added: boost the copy-user asm.
o added: merged IO-Stall fixes from 2.4.22-pre3/4/5/6/7
o added: q->full, defaults to off and keeps the elvtune changes.
So to turn on the q->full low latency fixes, you need to:
"elvtune -b 1 /dev/xxxx" . Note that for lvm and md, you need
to elvtune each underlying device. Running it on an lvm/md
device doesn't do anything.
o added: low latency / normal / max throughput - I/O elevator selection.
o fixed: CAN-2003-0461: /proc/tty/driver/serial reveals the exact
character counts for serial links. This could be used by a
local attacker to infer password lengths and inter-keystroke
timings during password entry.
o fixed: CAN-2003-0462: Paul Starzetz discovered a file read race
condition existing in the execve() system call, which could
cause a local crash.
o fixed: CAN-2003-0476: The execve system call in Linux 2.4.x records
the file descriptor of the executable process in the file
table of the calling process, allowing local users to gain
read access to restricted file descriptors.
o fixed: CAN-2003-0501: The /proc filesystem in Linux allows local users
to obtain sensitive information by opening various entries in
/proc/self before executing a setuid program. This causes the
program to fail to change the ownership and permissions of
already opened entries.
o fixed: CAN-2003-0550: The STP protocol is known to have no security,
which could allow attackers to alter the bridge topology.
STP is now turned off by default.
o fixed: CAN-2003-0551: STP input processing was lax in its length
checking, which could lead to a denial of service.
o fixed: CAN-2003-0552: Jerry Kreuscher discovered that the Forwarding
table could be spoofed by sending forged packets with bogus
source addresses the same as the local host.
o fixed: reduced the number of requests during seeks (the latency times
increased slightly during seeks with pre5/pre6).
o fixed: reserved some spare request for reads. This is been measured
to avoid some waiting for reads and it's beneficial in the
common case
o fixed: copy-namespace
o fixed: RMAP: refill free list in batches, in fixup_freespace
o fixed: RMAP: only wake up kswapd when low on free+clean pages
o fixed: RMAP: in __alloc_pages_limit, first do rmqueue (to use per-cpu
freelist) and fall back to direct_reclaim when needed
o fixed: RMAP: make sure the first stage of page allocation doesn't
upset the zone balancing
o updated: Oracle Cluster FileSystem (OCFS) v1.0.9-pre Jul 17 2003
o updated: AIO: allow aio on blkdevices too
o updated: smp-timers: merged an anti deadlock fix from lcm, 2.5 probably
needs it too. In short the theory that mod_timer is the only
thing that can run in parallel was wrong, add_timer and
del_timer/del_timer_sync can too. Having already fixed
mod_timer in a backwards compatible way before merging the
smp-timers in -aa, made it easy to fix those further windows
too.
o updated: ksoftirqd: merged a fix from Philip Craig to be sure to make
the anti-DoS logic effective. He wrote and verified the code.
It makes perfect sense so it's applied. Normal usages
shouldn't notice the difference, especially with the
max-loop logic.
o updated: Intel E100 driver v2.3.18-k1 + bugfixes from .22-BK
o updated: Intel E1000 driver v5.1.11-k1 + bugfixes from .22-BK
o updated: Broadcom BCM5700 driver v6.2.11
o updated: Broadcom Tigon3 v1.6
o updated: SysKonnect SK-98xx driver v6.12
o updated: HP CISS Driver v2.4.47
o updated: Compaq SMART2 Driver v2.4.25
o updated: raw vary-io 21, including more SCSI driver support
o updated: Super FreeS/WAN v1.99.8 Final
o updated: Qlogic QLA 2x00 v6 FC SCSI support v6.05.60
o removed: LUFS: braindamaged, non-working. Get rid of that shit.
o changed: DRM v4.3 is now seperate from DRM 4.0/4.1/4.2
md5sums:
- --------
d10045d3a42a5b2806fd9237674a8900 *linux-2.4.20-wolk4.3s-to-4.4s.patch.bz2
5eeac541fc5bd91e8d4290028e17bc44 *linux-2.4.20-wolk4.3s-to-4.4s.patch.gz
- --
Kind regards
Marc-Christian Petersen
http://sourceforge.net/projects/wolk
PGP/GnuPG Key: 1024D/569DE2E3DB441A16
Fingerprint: 3469 0CF8 CA7E 0042 7824 080A 569D E2E3 DB44 1A16
Key available at www.keyserver.net. Encrypted e-mail preferred.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: !! No Risk - No Fun !! - Try to crack this ;-)
iD8DBQE/J2oMVp3i49tEGhYRArz3AJ967NN3c3ksH5bjFjofUU1MyJoK7wCgw9hH
cA932m3WVf3WXFCZLOAY3fs=
=Fy3p
-----END PGP SIGNATURE-----
-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
_______________________________________________
WOLK - Working Overloaded Linux Kernel
[email protected]
https://lists.sourceforge.net/lists/listinfo/wolk-devel