svn commit: r49757 - in head/share: security/advisories security/patches/SA-16:39 xml
Xin LI <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.cvs.doc |
|---|---|
| Message-ID | <[email protected]> |
Author: delphij Date: Thu Dec 22 16:27:54 2016 New Revision: 49757 URL: https://svnweb.freebsd.org/changeset/doc/49757 Log: Add SA-16:39. Added: head/share/security/advisories/FreeBSD-SA-16:39.ntp.asc (contents, props changed) head/share/security/patches/SA-16:39/ head/share/security/patches/SA-16:39/ntp-10.x.patch (contents, props changed) head/share/security/patches/SA-16:39/ntp-10.x.patch.asc (contents, props changed) head/share/security/patches/SA-16:39/ntp-11.0.patch (contents, props changed) head/share/security/patches/SA-16:39/ntp-11.0.patch.asc (contents, props changed) head/share/security/patches/SA-16:39/ntp-9.3.patch (contents, props changed) head/share/security/patches/SA-16:39/ntp-9.3.patch.asc (contents, props changed) Modified: head/share/xml/advisories.xml Added: head/share/security/advisories/FreeBSD-SA-16:39.ntp.asc ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ head/share/security/advisories/FreeBSD-SA-16:39.ntp.asc Thu Dec 22 16:27:54 2016 (r49757) @@ -0,0 +1,239 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +============================================================================= +FreeBSD-SA-16:39.ntp Security Advisory + The FreeBSD Project + +Topic: Multiple vulnerabilities of ntp + +Category: contrib +Module: ntp +Announced: XXXX-XX-XX +Credits: Network Time Foundation +Affects: All supported versions of FreeBSD. +Corrected: 2016-11-22 16:22:51 UTC (stable/11, 11.0-STABLE) + 2016-12-22 16:19:05 UTC (releng/11.0, 11.0-RELEASE-p6) + 2016-11-22 16:23:20 UTC (stable/10, 10.3-STABLE) + 2016-12-22 16:19:05 UTC (releng/10.3, 10.3-RELEASE-p15) + 2016-12-22 16:19:05 UTC (releng/10.2, 10.2-RELEASE-p28) + 2016-12-22 16:19:05 UTC (releng/10.1, 10.1-RELEASE-p45) + 2016-11-22 16:23:46 UTC (stable/9, 9.3-STABLE) + 2016-12-22 16:19:05 UTC (releng/9.3, 9.3-RELEASE-p53) +CVE Name: CVE-2016-7426, CVE-2016-7427, CVE-2016-7428, CVE-2016-7431, + CVE-2016-7433, CVE-2016-7434, CVE-2016-9310, CVE-2016-9311 + +For general information regarding FreeBSD Security Advisories, +including descriptions of the fields above, security branches, and the +following sections, please visit <URL:https://security.FreeBSD.org/>. + +I. Background + +The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP) +used to synchronize the time of a computer system to a reference time +source. + +Trap is a mechanism to collect NTP daemon information from remote. + +II. Problem Description + +Multiple vulnerabilities have been discovered in the NTP suite: + +CVE-2016-9311: Trap crash, Reported by Matthew Van Gundy of Cisco ASIG. + +CVE-2016-9310: Mode 6 unauthenticated trap information disclosure and DDoS +vector. Reported by Matthew Van Gundy of Cisco ASIG. + +CVE-2016-7427: Broadcast Mode Replay Prevention DoS. Reported by +Matthew Van Gundy of Cisco ASIG. + +CVE-2016-7428: Broadcast Mode Poll Interval Enforcement DoS. Reported by +Matthew Van Gundy of Cisco ASIG. + +CVE-2016-7431: Regression: 010-origin: Zero Origin Timestamp Bypass. +Reported by Sharon Goldberg and Aanchal Malhotra of Boston University. + +CVE-2016-7434: Null pointer dereference in _IO_str_init_static_internal(). +Reported by Magnus Stubman. + +CVE-2016-7426: Client rate limiting and server responses. Reported by +Miroslav Lichvar of Red Hat. + +CVE-2016-7433: Reboot sync calculation problem. Reported independently +by Brian Utterback of Oracle, and by Sharon Goldberg and Aanchal Malhotra +of Boston University. + +III. Impact + +A remote attacker who can send a specially crafted packet to cause a +NULL pointer dereference that will crash ntpd, resulting in a Denial of +Service. [CVE-2016-9311] + +An exploitable configuration modification vulnerability exists in the +control mode (mode 6) functionality of ntpd. If, against long-standing +BCP recommendations, "restrict default noquery ..." is not specified, +a specially crafted control mode packet can set ntpd traps, providing +information disclosure and DDoS amplification, and unset ntpd traps, +disabling legitimate monitoring by an attacker from remote. [CVE-2016-9310] + +An attacker with access to the NTP broadcast domain can periodically +inject specially crafted broadcast mode NTP packets into the broadcast +domain which, while being logged by ntpd, can cause ntpd to reject +broadcast mode packets from legitimate NTP broadcast servers. +[CVE-2016-7427] + +An attacker with access to the NTP broadcast domain can send specially +crafted broadcast mode NTP packets to the broadcast domain which, while +being logged by ntpd, will cause ntpd to reject broadcast mode packets +from legitimate NTP broadcast servers. [CVE-2016-7428] + +Origin timestamp problems were fixed in ntp 4.2.8p6. However, subsequent +timestamp validation checks introduced a regression in the handling of +some Zero origin timestamp checks. [CVE-2016-7431] + +If ntpd is configured to allow mrulist query requests from a server +that sends a crafted malicious packet, ntpd will crash on receipt of +that crafted malicious mrulist query packet. [CVE-2016-7434] + +An attacker who knows the sources (e.g., from an IPv4 refid in server +response) and knows the system is (mis)configured in this way can +periodically send packets with spoofed source address to keep the rate +limiting activated and prevent ntpd from accepting valid responses +from its sources. [CVE-2016-7426] + +Ntp Bug 2085 described a condition where the root delay was included +twice, causing the jitter value to be higher than expected. Due to +a misinterpretation of a small-print variable in The Book, the fix +for this problem was incorrect, resulting in a root distance that did +not include the peer dispersion. The calculations and formulas have +been reviewed and reconciled, and the code has been updated accordingly. +[CVE-2016-7433] + +IV. Workaround + +No workaround is available, but systems not running ntpd(8) are not +affected. Network administrators are advised to implement BCP-38, +which helps to reduce the risk associated with these attacks. + +V. Solution + +Perform one of the following: + +1) Upgrade your vulnerable system to a supported FreeBSD stable or +release / security branch (releng) dated after the correction date. + +The ntpd service has to be restarted after the update. A reboot is +recommended but not required. + +2) To update your vulnerable system via a binary patch: + +Systems running a RELEASE version of FreeBSD on the i386 or amd64 +platforms can be updated via the freebsd-update(8) utility: + +# freebsd-update fetch +# freebsd-update install + +The ntpd service has to be restarted after the update. A reboot is +recommended but not required. + +3) To update your vulnerable system via a source code patch: + +The following patches have been verified to apply to the applicable +FreeBSD release branches. + +a) Download the relevant patch from the location below, and verify the +detached PGP signature using your PGP utility. + +[FreeBSD 11.0] +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-11.0.patch +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-11.0.patch.asc +# gpg --verify ntp-11.0.patch.asc + +[FreeBSD 10.x] +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-10.x.patch +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-10.x.patch.asc +# gpg --verify ntp-10.x.patch.asc + +[FreeBSD 9.3] +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-9.3.patch +# fetch https://security.FreeBSD.org/patches/SA-16:39/ntp-9.3.patch.asc +# gpg --verify ntp-9.3.patch.asc + +b) Apply the patch. Execute the following commands as root: + +# cd /usr/src +# patch < /path/to/patch + +c) Recompile the operating system using buildworld and installworld as +described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>. + +Restart the applicable daemons, or reboot the system. + +VI. Correction details + +The following list contains the correction revision numbers for each +affected branch. + +Branch/path Revision +- ------------------------------------------------------------------------- +stable/9/ r309009 +releng/9.3/ r310419 +stable/10/ r309008 +releng/10.1/ r310419 +releng/10.2/ r310419 +releng/10.3/ r310419 +stable/11/ r309007 +releng/11.0/ r310419 +- ------------------------------------------------------------------------- + +To see which files were modified by a particular revision, run the +following command, replacing NNNNNN with the revision number, on a +machine with Subversion installed: + +# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base + +Or visit the following URL, replacing NNNNNN with the revision number: + +<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN> + +VII. References + +<URL:http://support.ntp.org/bin/view/Main/SecurityNotice#November_2016_ntp_4_2_8p9_NTP_Se> + +<URL:https://www.kb.cert.org/vuls/id/633847> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7426> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7427> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7428> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7431> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7433> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7434> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9310> + +<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9311> + +The latest revision of this advisory is available at +<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-16:39.ntp.asc> +-----BEGIN PGP SIGNATURE----- +Version: GnuPG v2.1.16 (FreeBSD) + +iQIzBAEBCgAdFiEEHPf/b631yp++G4yy7Wfs1l3PaucFAlhb/kAACgkQ7Wfs1l3P +audQRhAA02Xpoz4mSF1Cz1gCgWAKpTNpB2fG5z8Pqv1q8BqdArr+ZH/G1g2L4E/b +Id/g8WUvpZLozTeuWMx/6dm/XCbI+OhbzasZp46Cak3o2LMB6v3OC43qVX8fQiiO +9GgCltR6I8V939MVFKxo+cdflqIwmguKdLJHvnin8mv8MAjXOG7rrAx+FqcQjJ5i +oATuFLj/A9kWDiRH4TAQr/rVRmJGmIQY2GpEMt7oB/1ho5HFGhIdNZLCuriIcAGZ +HpZJoNKmDHV3mOfM+C03e4otBaoX6asid2TiY5lnDMx4j+a+Gxdv5tWnt72Bn0X/ +EC5HWYjm7QFDg/hfrymBfT7cObuVKtdEJikkRw3huBy6RN6d4zsaTJFMIODl6sNs +zBE5+vrwcXiUrbic10RoVzeSEFdVh7C6Ji1OK/rsxXAbgs0zkoHua/nxO2fhdyHr +m3Mb59QE7TiM1zaMjks1QZXORo53CrGHrhE6Qi7sISO0SS4mWCOkulOZeNjXQ3xK +GFox3YV0WDZz4m7VjZQS6/pj+dO4sABVQ0mahydJJX35FVkdJuknv/98yxmYRuHG +jP9NTUEh6dGDT3w/57hGg7VIgTR47q3e6UbutrqNoxiV5Br465mb9LxMjngDW7bA +poe9XHFMCmFV96gYN2va2cENUM/PjWI8mHWjZShG5DCXMVnK64A= +=PDXk +-----END PGP SIGNATURE----- Added: head/share/security/patches/SA-16:39/ntp-10.x.patch ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ head/share/security/patches/SA-16:39/ntp-10.x.patch Thu Dec 22 16:27:54 2016 (r49757) @@ -0,0 +1,17239 @@ +--- contrib/ntp/ChangeLog.orig ++++ contrib/ntp/ChangeLog +@@ -1,4 +1,73 @@ + --- ++(4.2.8p9) 2016/11/21 Released by Harlan Stenn <[email protected]> ++(4.2.8p9) 2016/MM/DD Released by Harlan Stenn <[email protected]> ++ ++* [Sec 3119] Trap crash <[email protected]> ++* [Sec 3118] Mode 6 information disclosure and DDoS vector <[email protected]> ++ - TRAP config via mode 6 packet requires AUTH now. ++* [Sec 3114] Broadcast Mode Replay Prevention DoS ++ - applied patches by Matthew Van Gundy. <[email protected]> ++ - with bcpollbstep, tweaks and cleanup by [email protected] ++* [Sec 3113] Broadcast Mode Poll Interval Enforcement DoS <[email protected]> ++ - applied fix as suggested by Matthew Van Gundy ++* [Sec 3110] Windows: ntpd DoS by oversized UDP packet ++ - fixed error handling for truncated UDP packets. <[email protected]> ++* [Sec 3102] Zero origin issues. HStenn. ++* [Sec 3082] null pointer dereference in _IO_str_init_static_internal() ++ - more hardening to read_mru_list(). [email protected] ++* [Sec 3072] Attack on interface selection <[email protected]> ++ - implemented Miroslav Lichvars <[email protected]> suggestion ++ to skip interface updates based on incoming packets ++* [Bug 3142] bug in netmask prefix length detection <[email protected]> ++* [Bug 3138] gpsdjson refclock should honor fudgetime1. [email protected] ++* [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ - moved retry decision where it belongs. <[email protected]> ++* [Bug 3125] NTPD doesn't fully start when ntp.conf entries are out of order ++ using the loopback-ppsapi-provider.dll <[email protected]> ++* [Bug 3116] unit tests for NTP time stamp expansion. <[email protected]> ++* [Bug 3100] ntpq can't retrieve daemon_version <[email protected]> ++ - fixed extended sysvar lookup (bug introduced with bug 3008 fix) ++* [Bug 3095] Compatibility with openssl 1.1 <[email protected]> ++ - applied patches by Kurt Roeckx <[email protected]> to source ++ - added shim layer for SSL API calls with issues (both directions) ++* [Bug 3089] Serial Parser does not work anymore for hopfser like device ++ - simplified / refactored hex-decoding in driver. <[email protected]> ++* [Bug 3084] update-leap mis-parses the leapfile name. HStenn. ++* [Bug 3068] Linker warnings when building on Solaris. [email protected] ++ - applied patch thanks to Andrew Stormont <[email protected]> ++* [Bug 3067] Root distance calculation needs improvement. HStenn. ++* [Bug 3066] NMEA clock ignores pps. [email protected] ++ - PPS-HACK works again. ++* [Bug 3059] Potential buffer overrun from oversized hash <[email protected]> ++ - applied patch by Brian Utterback <[email protected]> ++* [Bug 3053] ntp_loopfilter.c frequency calc precedence error. Sarah White. ++* [Bug 3050] Fix for bug #2960 causes [...] spurious error message. ++ <[email protected]> ++ - patches by Reinhard Max <[email protected]> and Havard Eidnes <[email protected]> ++* [Bug 3047] Fix refclock_jjy C-DEX JST2000. [email protected] ++ - Patch provided by Kuramatsu. ++* [Bug 3021] unity_fixture.c needs pragma weak <[email protected]> ++ - removed unnecessary & harmful decls of 'setUp()' & 'tearDown()' ++* [Bug 3019] Windows: ERROR_HOST_UNREACHABLE block packet processing. ++ DMayer and JPerlinger. ++* [Bug 2998] sntp/tests/packetProcessing.c broken without openssl. JPerlinger ++* [Bug 2961] sntp/tests/packetProcessing.c assumes AUTOKEY. HStenn. ++* [Bug 2959] refclock_jupiter: gps week correction <[email protected]> ++ - fixed GPS week expansion to work based on build date. Special thanks ++ to Craig Leres for initial patch and testing. ++* [Bug 2951] ntpd tests fail: multiple definition of `send_via_ntp_signd' ++ - fixed Makefile.am <[email protected]> ++* [Bug 2689] ATOM driver processes last PPS pulse at startup, ++ even if it is very old <[email protected]> ++ - make sure PPS source is alive before processing samples ++ - improve stability close to the 500ms phase jump (phase gate) ++* Fix typos in include/ntp.h. ++* Shim X509_get_signature_nid() if needed. ++* git author attribution cleanup ++* bk ignore file cleanup ++* remove locks in Windows IO, use rpc-like thread synchronisation instead ++ ++--- + (4.2.8p8) 2016/06/02 Released by Harlan Stenn <[email protected]> + + * [Sec 3042] Broadcast Interleave. HStenn. +@@ -19,7 +88,7 @@ + * Fix typo in ntp-wait and plot_summary. HStenn. + * Make sure we have an "author" file for git imports. HStenn. + * Update the sntp problem tests for MacOS. HStenn. +- ++ + --- + (4.2.8p7) 2016/04/26 Released by Harlan Stenn <[email protected]> + +--- contrib/ntp/CommitLog.orig ++++ contrib/ntp/CommitLog +@@ -1,3 +1,1866 @@ [email protected], 2016-11-21 08:08:21-05:00, [email protected] ++ NTP_4_2_8P9 ++ TAG: NTP_4_2_8P9 ++ ++ [email protected] +1 -0 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +1 -1 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +1 -1 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +157 -154 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +21 -33 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +245 -245 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +142 -186 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +106 -106 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +75 -95 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpdc/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +113 -113 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +136 -160 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpq/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +67 -67 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +10 -14 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ ntpsnmpd/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ [email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +30 -42 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/calc_tickadj/[email protected] +1 -1 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +41 -59 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntp-wait/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +46 -57 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntpsweep/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +38 -47 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/ntptrace/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +40 -58 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +37 -49 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +1 -1 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +48 -72 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ scripts/update-leap/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +158 -158 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +111 -135 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ sntp/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +172 -172 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +157 -216 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +3 -3 ++ NTP_4_2_8P9 ++ ++ util/[email protected] +2 -2 ++ NTP_4_2_8P9 ++ [email protected], 2016-11-21 07:07:04-05:00, [email protected] ++ ntp-4.2.8p9 ++ ++ [email protected] +1 -1 ++ ntp-4.2.8p9 ++ [email protected], 2016-11-21 03:47:58+00:00, [email protected] ++ NEWS updates, final p9 testing ++ ++ [email protected] +25 -17 ++ NEWS updates, final p9 testing ++ ++ [email protected] +2 -2 ++ NEWS updates, final p9 testing ++ [email protected], 2016-11-18 10:33:02+00:00, [email protected] ++ NEWS update for 3142 ++ ++ [email protected] +2 -1 ++ NEWS update for 3142 ++ [email protected], 2016-11-18 08:55:13+01:00, [email protected] ++ [Bug 3142] bug in netmask prefix length detection ++ ++ [email protected] +3 -0 ++ [Bug 3142] bug in netmask prefix length detection ++ ++ lib/isc/[email protected] +0 -1 ++ [Bug 3142] bug in netmask prefix length detection ++ [email protected], 2016-11-16 21:25:49-08:00, [email protected] ++ NEWS file update ++ ++ [email protected] +7 -22 ++ NEWS file update ++ [email protected], 2016-11-13 21:59:31-08:00, [email protected] ++ cleanup ++ ++ [email protected] +201 -77 ++ cleanup ++ [email protected], 2016-11-13 21:56:18-08:00, [email protected] ++ cleanip ++ ++ [email protected] +2 -0 ++ cleanip ++ [email protected], 2016-11-13 02:43:02+00:00, [email protected] ++ NEWS updates ++ ++ [email protected] +17 -0 ++ NEWS updates ++ [email protected], 2016-11-13 02:30:31+00:00, [email protected] ++ NEWS cleanup ++ ++ [email protected] +2 -0 ++ NEWS cleanup ++ [email protected], 2016-11-12 17:36:54-08:00, [email protected] ++ NEWS cleanup ++ ++ [email protected] +41 -6 ++ NEWS cleanup ++ [email protected], 2016-11-12 16:55:59-08:00, [email protected] ++ [Bug 3067] Root distance calculation needs improvement. HStenn ++ ++ [email protected] +1 -0 ++ [Bug 3067] Root distance calculation needs improvement. HStenn ++ ++ [email protected] +1 -0 ++ [Bug 3067] Root distance calculation needs improvement. HStenn ++ ++ ntpd/[email protected] +16 -11 ++ [Bug 3067] Root distance calculation needs improvement. HStenn ++ [email protected], 2016-11-12 15:57:34-08:00, [email protected] ++ [Bug 3138] gpsdjson refclock should honor fudgetime1. [email protected] ++ ++ [email protected] +1 -0 ++ [Bug 3138] gpsdjson refclock should honor fudgetime1. [email protected] ++ ++ [email protected] +1 -0 ++ [Bug 3138] gpsdjson refclock should honor fudgetime1. [email protected] ++ ++ ntpd/[email protected] +1 -1 ++ [Bug 3138] gpsdjson refclock should honor fudgetime1. [email protected] ++ [email protected], 2016-11-12 05:54:39+01:00, [email protected] ++ [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ ++ [email protected] +4 -0 ++ [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ ++ include/[email protected] +6 -0 ++ [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ - add flags and prototype for 'getaddrinfo_sometime_ex()' ++ ++ libntp/[email protected] +48 -14 ++ [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ - implement 'getaddrinfo_sometime_ex()', support ignoring all errors ++ ++ ntpd/[email protected] +11 -10 ++ [Bug 3129] Unknown hosts can put resolver thread into a hard loop ++ - move decison about igoring DNS errors to resolver code ++ [email protected], 2016-11-09 12:32:07+00:00, [email protected] ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ [email protected] +1 -1 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ html/[email protected] +4 -2 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ include/[email protected] +1 -0 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ include/[email protected] +1 -0 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +1 -1 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +16 -1 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +1 -1 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +1 -0 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +29 -8 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +21 -2 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +19 -0 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +29 -8 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +21 -2 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +15 -0 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +1068 -1058 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +1196 -1193 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +373 -371 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +3 -1 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ ++ ntpd/[email protected] +43 -26 ++ [Bug 3114] bcpollbstep, tweaks and cleanup ++ [email protected], 2016-11-09 06:06:04+00:00, [email protected] ++ typo ++ ++ [email protected] +1 -1 ++ typo ++ [email protected], 2016-11-08 20:01:41+01:00, [email protected] ++ [Bug 3089] Serial Parser does not work anymore for hopfser like device ++ ++ [email protected] +4 -0 ++ [Bug 3089] Serial Parser does not work anymore for hopfser like device ++ ++ libparse/[email protected] +43 -25 ++ [Bug 3089] Serial Parser does not work anymore for hopfser like device ++ - simplified / refactored hex-decoding in driver. ++ [email protected], 2016-11-03 17:02:24-07:00, [email protected] ++ Added leap smear/root dispersion comment ++ ++ ntpd/[email protected] +4 -0 ++ Added leap smear/root dispersion comment ++ [email protected], 2016-10-31 10:56:33+00:00, [email protected] ++ Add bug 3125 to the NEWS file ++ ++ [email protected] +2 -0 ++ Add bug 3125 to the NEWS file ++ [email protected], 2016-10-24 07:37:25+02:00, [email protected] ++ [winio2 - unlocked] ++ - the great lock removal ++ - the great renaming ++ ++ [email protected] +1 -0 ++ [winio2 - unlocked] notes on changes ++ ++ ntpd/[email protected] +1 -1 ++ [winio2 - unlocked] ++ - whitespace at EOL ++ ++ ports/winnt/include/[email protected] +21 -24 ++ [winio2 - unlocked] ++ - eliminate critical section, simplify API ++ - the great renaming ++ ++ ports/winnt/ntpd/[email protected] +331 -209 ++ [winio2 - unlocked] ++ - the great lock removal ++ - handle context objects are only manipulated by IOCPL thread ++ - closing handles is done by main thread after informing IOCPL thread (RPC-style) ++ - the great renaming ++ - restructured UNIX line mode emulation ++ ++ ports/winnt/ntpd/[email protected] +31 -95 ++ [winio2 - unlocked] ++ - eliminate critical section, simplify API ++ - the great renaming ++ ++ [email protected], 2016-10-23 05:18:04+00:00, [email protected] ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +1 -1 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +1 -1 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +104 -91 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +29 -17 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +245 -245 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +146 -102 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpd/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +106 -106 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +77 -57 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpdc/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +113 -113 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +3 -3 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +2 -2 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +129 -105 ++ ntp-4.2.8p9-PRE ++ ++ ntpq/[email protected] +3 -3 *** DIFF OUTPUT TRUNCATED AT 1000 LINES *** _______________________________________________ [email protected] mailing list https://lists.freebsd.org/mailman/listinfo/svn-doc-all To unsubscribe, send any mail to "[email protected]"