9:52 AM - src compiles
Just an FYI, buildworld and buildkernel are working again. I'm running both on the servers. The OpenSSH update appears to have worked fine.
Just an FYI, buildworld and buildkernel are working again. I'm running both on the servers. The OpenSSH update appears to have worked fine.
dmesg
Copyright (c) 2006 The MidnightBSD Project.
Copyright (c) 1992-2006 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
MidnightBSD 0.1-PRERELEASE #0: Mon Oct 9 01:27:25 EDT 2006
laffer1@stargazer.midnightbsd.org:/usr/obj/usr/src/sys/SMP
ACPI APIC Table:
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) Xeon(TM) CPU 2.00GHz (1993.58-MHz 686-class CPU)
Origin = "GenuineIntel" Id = 0xf27 Stepping = 7
Features=0xbfebfbff
Features2=0x4400
Hyperthreading: 2 logical CPUs
real memory = 1073172480 (1023 MB)
avail memory = 1041076224 (992 MB)
ioapic0: Changing APIC ID to 8
ioapic1: Changing APIC ID to 9
ioapic2: Changing APIC ID to 10
ioapic0
ioapic1
ioapic2
kbd1 at kbdmux0
npx0: [FAST]
npx0:
The kernel is compiling again in src. I'm testing it so i don't know how stable it is yet.
dmesg
Copyright (c) 2006 The MidnightBSD Project.
Copyright (c) 1992-2006 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
MidnightBSD 0.1-PRERELEASE #2: Thu Oct 12 14:55:44 EDT 2006
laffer1@enterprise.midnightbsd.org:/usr/obj/usr/src/sys/GENERIC
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Pentium III/Pentium III Xeon/Celeron (546.33-MHz 686-class CPU)
Origin = "GenuineIntel" Id = 0x673 Stepping = 3
Features=0x383fbff
real memory = 536862720 (511 MB)
avail memory = 515997696 (492 MB)
ACPI APIC Table:
ioapic0: Changing APIC ID to 1
ioapic0
kbd1 at kbdmux0
npx0: [FAST]
npx0:
Today i've continued work on restoring the source tree. I just did some minor changes to the website including removing the bit torrent link and sending people to the ftp server. I'll fix the www and torrent links when we do a release. Its just easier for snaps to leave it like this for now. I also placed a link to the forum on the first page. Some people have had trouble finding it.
Not to sound like an MSDN newsletter, but its snowing here!
The website was down due to a hardware swap out. I replaced the existing "server" with my workstation. The old system was an amd sempron 2300+ with 768mb ram, 80gb ide, 2x 80gb sata raid 1. The new setup is a Dell Precision 650 workstation with 2 intel xeon 2.0Ghz processors, the above mentioned IDE disk and a 76GB seagate U160 scsi disk. The sata raid was very unstable on the msi board. I suspect the nforce2 sata raid controller was a bit flaky. Regardless, the precision has been used to build releases up to this point so its fairly stable.
The upside is that my new system is a Pentium D 805 so I will be able to support AMD64/EMT64 releases in the future.
I've made a few minor changes to the boot/loader code this morning. The changes should fix problems with some HP/Compaq computers and the general size of the boot2 code should be a bit smaller.
I also looked at the report about the boot menu specifying FreeBSD. I could easily change the code to simply print BSD as it does for all other BSD systems. I'll hold off on that change until the other boot changes are verified.
On the topic of OpenSSH, raven has been delayed finishing the work.
I've also researched the dri/drm reports a bit. Our dri code matches the code in FBSD 6.1 Release. There have been recent commits to fix a few things, notably the intel 945 chipset. I may look at importing those later. Until we get a newer xorg version in ports, it won't make much difference.
The timezone issue should be resolved with the installer and while running tzsetup.
TODO: remove some of the alpha code in boot, etc. Consider importing bzip2 changes for boot when they are finished. Look into upgrading xorg to 7.x.
The problem with the installer is related to an error reading /usr/share/zoneinfo/zone.tab with the tzsetup command. The installer actually calls that program to setup timezones during install. It is the source of the reported problem.
A great number of ports were added today. java ports are now abundant including freebsd jdk (binary) and linux-sun-jdk* as well as jedit, bluej, and various libraries.
We are getting closer to an openoffice build. There is one remaining dependancy that must be commited before we can do a test build. (version 1.1) I'm hoping it works as planned. With java in ports, we have a good chance now of getting it to work.
ORBit was added today and I'm working on GCC 3.3 (needed for openoffice). linux-realplayer was added to multimedia and although that category is a bit lacking, we should have basics covered. We'll look at getting mplayer and xine to work later.
I'm hoping I can add tomcat soon as that would give us a java development environment for writing web applications which I would personally find quite useful.
If there are ports that you think are needed for a desktop system, please e-mail me or post on the MidnightBSD forum (http://forums.midnightbsd.org/)
Yesterday, a number of useful ports were added. MySQL 5.0, qemu, wine, sdl 1.2, bind 9, and bochs were added to mports.
The OpenSSH port is still in progress. A large number of changes need to be manually merged with this release. Raven is working on the problem.
This week, we've gained a commiter and two more have asked to join the project. Presuming the OpenSSH problem is resolved soon, we should be able to build a beta this weekend. I'm testing the last snapshot today. Others have reported successful installs with disk1 iso.
The OpenSSH 4.4p1 update is in progress and as such head is most likely not compiling safely. I'll post a new entry when its safe.
A number of security issues were found in OpenSSL. The patch was added to MidnightBSD tonight to fix these issues. It is not included in the recent snapshot. Users are encouraged to update their source and rebuild the world. OpenSSH has not been patched yet.
Here is the advisory as posted on the OpenSSL website:
OpenSSL Security Advisory [28th September 2006]
New OpenSSL releases are now available to correct four security
issues.
ASN.1 Denial of Service Attacks (CVE-2006-2937, CVE-2006-2940)
==============================================================
Vulnerability
-------------
Dr. S. N. Henson recently developed an ASN.1 test suite for NISCC
(www.niscc.gov.uk). When the test suite was run against OpenSSL two
denial of service vulnerabilities were discovered:
1. During the parsing of certain invalid ASN.1 structures an error
condition is mishandled. This can result in an infinite loop which
consumes system memory (CVE-2006-2937). (This issue did not affect
OpenSSL versions prior to 0.9.7)
2. Certain types of public key can take disproportionate amounts of
time to process. This could be used by an attacker in a denial of
service attack (CVE-2006-2940).
Any code which uses OpenSSL to parse ASN.1 data from untrusted sources
is affected. This includes SSL servers which enable client
authentication and S/MIME applications.
Acknowledgements
----------------
The OpenSSL team thank Dr S. N. Henson of Open Network Security and NISCC
for funding the ASN.1 test suite project.
SSL_get_shared_ciphers() buffer overflow (CVE-2006-3738)
========================================================
Vulnerability
-------------
A buffer overflow was discovered in the SSL_get_shared_ciphers()
utility function. An attacker could send a list of ciphers to an
application that uses this function and overrun a buffer
(CVE-2006-3738).
Acknowledgements
----------------
The OpenSSL team thank Tavis Ormandy and Will Drewry of the Google
Security Team for reporting this issue.
SSLv2 Client Crash (CVE-2006-4343)
==================================
Vulnerability
-------------
A flaw in the SSLv2 client code was discovered. When a client
application used OpenSSL to create an SSLv2 connection to a malicious
server, that server could cause the client to crash (CVE-2006-4343).
Acknowledgements
----------------
The OpenSSL team thank Tavis Ormandy and Will Drewry of the Google
Security Team for reporting this issue.
Recommendations
===============
These vulnerabilities are resolved in the following versions of OpenSSL:
- in the 0.9.7 branch, version 0.9.7l (or later);
- in the 0.9.8 branch, version 0.9.8d (or later).
OpenSSL 0.9.8d and OpenSSL 0.9.7l are available for download via
HTTP and FTP from the following master locations (you can find the
various FTP mirrors under http://www.openssl.org/source/mirror.html):
o http://www.openssl.org/source/
o ftp://ftp.openssl.org/source/
The distribution file names are:
o openssl-0.9.8d.tar.gz
MD5 checksum: 8ed1853538e1d05a1f5ada61ebf8bffa
SHA1 checksum: 4136fba00303a3d319d2052bfa8e1f09a2e12fc2
o openssl-0.9.7l.tar.gz
MD5 checksum: b21d6e10817ddeccf5fbe1379987333e
SHA1 checksum: f0e4136639b10cbd1227c4f7350ff7ad406e575d
The checksums were calculated using the following commands:
openssl md5 openssl-0.9*.tar.gz
openssl sha1 openssl-0.9*.tar.gz
After upgrading make sure to recompile any applications statically
linked to OpenSSL libraries and restart all applications that use
OpenSSL.
References
==========
URL for this Security Advisory:
http://www.openssl.org/news/secadv_20060928.txt
A new snapshot was posted. This version includes the recent zlib update, changes to ports including mports compatibility, and src changes up through this evening.
zlib 1.2.3 was imported and patched tonight.
A goal was set to release a beta version this weekend of 0.1 release. We do not feel that we are ready for this beta release. There are a few issues with the new ports sytem that we'd like to resolve.
The OpenSSL and OpenSSH security updates have not been applied to the base. Beware of this issue. Archite is working on the patches.
rsync and netcat were added to mports this weekend.
Changes have been made to GENERIC. 486 support has been removed. The current installer requires a large amount of RAM for 486 machines and the decision was made to remove support. We hope to improve the memory footprint on lowend hardware, but considering we are moving on with GNUstep and xorg will be running it doesn't make sense to continue supporting 486 processors. We hope to shrink the size of our default kernel by removing some options that can be handled with modules or are not needed by most users. Support for RIO mp3 players has been commented out in the configuration as well.
mports index building has been fixed. The make fetchindex target was pointed at the MidnightBSD website and we will start building indexes soon for inclusion there.
It appears my Ultra 10 3d creator died. I am no longer able to test Sparc64 versions of MidnightBSD. I'm still attempting to fix this, but it doesn't look good.
location: Home