Showing posts with label oct. Show all posts
Showing posts with label oct. Show all posts

Sunday, June 18, 2017

NetBSD 7.1 released (March 11, 2017)

NetBSD 7.1 released (March 11, 2017)

Introduction

The NetBSD Project is pleased to announce NetBSD 7.1, the first feature update of the NetBSD 7 release branch. It represents a selected subset of fixes deemed important for security or stability reasons, as well as new features and enhancements.
Some highlights of the 7.1 release are:
  • Support for Raspberry Pi Zero.
  • Initial DRM/KMS support for NVIDIA graphics cards via nouveau (Disabled by default. Uncomment nouveau and nouveaufb in your kernel config to test).
  • The addition of vioscsi, a driver for the Google Compute Engine disk.
  • Linux compatibility improvements, allowing, e.g., the use of Adobe Flash Player 24.
  • wm(4):
    • C2000 KX and 2.5G support.
    • Wake On Lan support.
    • 82575 and newer SERDES based systems now work.
  • ODROID-C1 Ethernet now works.
  • Numerous bug fixes and stability improvements.
Complete source and binaries for NetBSD 7.1 are available for download at many sites around the world. A list of download sites providing FTP, AnonCVS, SUP, and other services may be found athttp://www.NetBSD.org/mirrors/. We encourage users who wish to install via ISO or USB disk images to download via BitTorrent by using the torrent files supplied in the images area. A list of hashes for the NetBSD 7.1 distribution has been signed with the well-connected PGP key for the NetBSD Security Officer: http://ftp.NetBSD.org/pub/NetBSD/security/hashes/NetBSD-7.1_hashes.asc
NetBSD is free. All of the code is under non-restrictive licenses, and may be used without paying royalties to anyone. Free support services are available via our mailing lists and website. Commercial support is available from a variety of sources. More extensive information on NetBSD is available from our website:

Changes Between 7.0.2 and 7.1

Below is an abbreviated list of changes in this release. Note that all of the changes found in NetBSD 7.0.1 and NetBSD 7.0.2 are present in this release. The complete list of changes can be found in the CHANGES-7.1 file in the top level directory of the NetBSD 7.1 release tree.

Security Advisory Fixes

The following security advisories were fixed:
Note: Advisories prior to NetBSD-SA2017-001 do not affect NetBSD 7.0.2.

Other Security Fixes

  • BIND: Update to 9.10.4-P6, fixing CVE-2017-3135.
  • expat: Update to 2.2.0, fixing CVE-2016-0718, CVE-2016-4472, CVE-2016-5300, and CVE-2012-6702.
  • ISC DHCP: Fix CVE-2015-8605.
  • libICE: Fix CVE-2017-2626.
  • OpenSSL: Fix CVE-2016-7056 and CVE-2017-3731.
  • tcpdump: Update to 4.9.0, fixing CVE-2014-8767, CVE-2014-8768, CVE-2014-9140, CVE-2015-0261, CVE-2015-2153, CVE-2015-2154, CVE-2015-2155, CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925, CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930, CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935, CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940, CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984, CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574, CVE-2016-8575, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205, CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484, CVE-2017-5485, and CVE-2017-5486.
  • xorg-server: Fix CVE-2017-2624.

General kernel

  • Add net.inet.arp.log_unknown_network sysctl(7) to selectively log ARP packets from non-local networks.
  • Allow binding to detached IPv6 addresss. PR 51435.
  • carp(4): Fix an issue in mixed IPv4/IPv6 environments where a carp interface tries to get MASTER status even though the master is still advertising.
  • compat_linux(8): Fully support sched_setaffinity and sched_getaffinity, fixing, e.g., the Intel Math Kernel Library. PR 50021.
  • compat_netbsd32(8): Add support for nfssvc(2).
  • DTrace:
    • Avoid redefined symbol errors when loading the module.
    • Fix module autoload.
  • In kernel configuration files, it is now possible to specify a wedge name (e.g., "wedge:NAME") as a root device.
  • IPFilter:
    • Fix matching of ICMP queries when NAT'd through IPF.
    • Fix lookup of original destination address when using a redirect rule. This is required for transparent proxying by squid, for example.
  • ipsec(4): Fix NAT-T issue with NetBSD being the host behind NAT.
  • NFS: Fix soft force unmount.
  • npf(7): Handle delayed checksums for IPv6.
  • procfs: Maps don't change that frequently between reads, so allow reading from an offset. Notably, this makes the Linux Flash player 24 work.
  • SACK: Fix issue that resulted in, e.g., dropped SSH connections. PR 51753.

Drivers

  • Add vioscsi driver for the Google Compute Engine disk.
  • btmagic(4): Add support for Apple Magic Trackpad.
  • ichlpcib(4):
    • Add Core 5G (mobile) LPC support.
    • Disable gpio(4) attachment by default, fixing resume for some machines. GPIO functionality can be enabled by setting ichlpcib_gpio_disable to 0, for instance with "gdb -write". PR 50733.
  • ichsmb(4): Add support for Braswell CPU and Intel 100 Series.
  • iwn(4): Fix issue connecting to 5GHz access points. PR 50187.
  • ixgbe(4): Fix various bugs and crashes.
  • puc(4):
    • Add support for SystemBase SB16C1050 PCI serial card. PR 49819.
    • Add support for another Intel Q45 KT.
    • Add support for Intel 100 Series Chipset KT.
  • sdtemp(4):
    • Add support for Atmel AT30TS00, AT30TSE004, Giantec GT30TS00, GT34TS02, Microchip MCP9804, MCP98244, IDT TS3000GB[02], TS3001GB2, TSE2004GB2, On Semiconductor CAT34TS02C and CAT34TS04.
    • Add JEDEC TSE2004av support.
    • Fix temperature resolution on some devices.
    • Show accuracy, range, resolution, high voltage standoff and shutdown.
  • uchcom(4): Make newer (0x30-on) CH340 devices work.
  • uplcom(4): Avoid a kernel page fault when opening the device.
  • ucom(4): Add the port number to the device properties to make it easier to relate a specific ucom instance with the physical port of multi-port devices like the FTDI 4232.
  • wd(4): Put the drive in standby before detach when powering off the system. PR 51252.
  • wm(4):
    • Add C2000 KX and 2.5G support.
    • Add Wake On Lan support.
    • Fix a lot of bugs to make 82575 and newer SERDES based systems work.
    • Fix a bug where the input drop packet counter is not counted correctly.
    • Fix a problem where I210 and I211 sometimes don't have a link if the NVM image version is less than 3.25.
    • Fix a problem where 82574 and 82583 sometimes drop packets if the NVM image version is less than 2.1.4.
    • Fix a bug where some Intel AMT based systems don't linkup at 1000BaseT. PR 44893.
    • Fix bugs to make ICH and PCH devices stable.
    • Disable Low Power Link Up function correctly.
    • Improve the behavior of suspend/resume on 82544 and newer chips.
    • Avoid chip hang on 82575 and newer devices.

Platforms

  • alpha: Fix buffer overflow causing wrong host controller SCSI ID for DEC 3000.
  • arm:
    • Add Raspberry Pi Zero support.
    • Fix pmap regression that prevented XScale-based boards from booting.
    • Fix X server on big endian ARM systems. PR 50356.
    • Fix ODROID-C1 Ethernet.
    • Support 8-bit eMMC for TI AM335x.
  • dreamcast: Fix panic after wsconscfg(8) from serial console.
  • luna68k:
    • Make kernel work with 8kB/page (PGSHIFT==13) settings.
    • Add preliminary support for LUNA's HD647180X I/O processor (aka XP).
  • macppc:
    • adb(4):
      • Ask the keyboard to distinguish between left and right Control, Alt, and Shift keys.
      • Add us.dvorak keymap variant. PR 51255.
  • mips:
    • Fix a crash related to executing N64 binaries.
    • Lemote YeeLoong:
      • Fix Xorg.
      • Fix screen blanking.
      • ohci(4): Make low-speed and full-speed devices work.
  • powerpc: Fix single precision floating point arithmetic. PR 51368.
  • sandpoint:
    • altboot:
      • Correctly identify and power up a second disk on the same SATA channel.
      • Fix misdetection of LinkStation and KuroBox(HG) as KuroT4.
    • Fix panic in sandpoint DIAGNOSTIC kernel.
  • sparc64:
    • Restore binary compatibility for old binaries.
    • Fix interrupt routing on machines with Tomatillo PCI controllers.
  • x68k:
    • Fix poweroff.
    • Fix crashdump on machines with EXTENDED_MEMORY. PR 51663.
  • x86 (amd64i386):
    • Add initial DRM/KMS support for NVIDIA graphics cards via nouveau. Disabled by default, but can be enabled by uncommenting the nouveau and nouveaufb drivers in the GENERIC kernel config file, building a new kernel, and configuring X to use the nouveau driver instead of nv.
    • procfs:
      • Always output 2 digits for the CPU frequency decimal part.
      • Numerous improvements to make /proc/cpuinfo more informative and accurate. PRs 49246 and 39950.
  • xen:
    • Add machdep.xen.version sysctl(7) to easily get hypervisor version.
    • Make Xen process and file limits match the native ones.

Userland

  • blacklistctl(8): Make -n actually work.
  • cat(1): When invoked with -se, print a '$' on blank lines. PR 51250.
  • cp(1): Make the '-i' flag work regardless of whether the standard input is a terminal.
  • cpuctl(8) Add data for newer x86 CPUs.
  • dump(8):
    • Default the read block size for dump to kern.maxphys. This gives a noticable performance boost on large filesystems.
    • Fix tape usage report for large filesystems.
    • Allow file system pathname lengths greater than 16 characters. PR 50434.
  • db(3): Fix handling of 64k blocksize, which overflows a uint16_t. PR 50441.
  • ftp(1):
    • Handle proxy authentication correctly.
    • Fix crash in ftp when given an IPv6 URL that's missing a slash. PR 51558.
    • CONNECT method support.
    • Use the proper format "[IPv6 address]:port" when reporting connection attempts to IPv6 endpoints.
    • Fix downloads of local files using file:// URLs.
    • Add Server Name Indication (SNI) support for https.
  • getpass(3): Fix a bug where ctrl-c in a password prompt resulted in tty settings not being restored. PR 50695.
  • iostat(8): Support fnmatch(3) patterns for disknames. For example, "iostat wd*" works now.
  • jemalloc(3): Avoid long linear searches for code heavy on medium sized allocations. PR 50791.
  • ld.elf_so(1):
    • Add basic support for indirect functions. It allows providing a public function symbol with an implementation choosen at run time.
    • Fix deadlocks. PRs 49813 and 49816.
  • man(1): Make "man /" work again.
  • opendisk(3): Instead of trying to open files in the current working directory first for paths that don't contain "/", first try the /dev paths to avoid confusion with files in the working directory that happen to match disk names. PR 51216.
  • pthread_key_create(3): Make PTHREAD_KEYS_MAX dynamically adjustable.
  • racoon(8):
    • Fix memory leak. PR 50918.
    • Allow using IKE Mode Config in a plain "rsasig" (signed certificates only) configurations.
  • resize_ffs(8): Fix handling of ffsv2 inode initialization. PR 51116.
  • scsictl(8): Add "getrealloc" and "setrealloc" commands to get/set automatic reallocation parameters/enables for error recovery, similar to {get,set}cache.
  • sh(1):
    • Fix the parsing of references to shell parameters when given without braces (i.e., $2). Only the first 9 shell parameters ($1 .. $9) and the special parameter ($0) can be referenced this way, $10 is ${1}0 not ${10}. PR 51027 .
    • Process pending signals while waiting for a job, and report the signal that wait was interrupted by.
  • stdio(3): Allow changing the default buffering policy for a stdio stream during construction by setting environment variables. See setbuf(3).
  • terminfo(3): Fix memory leaks. PR 50092.
  • mv(1): Add support for SIGINFO.
  • libperfuse(3): Make FUSE socket buffer tunable through the PERFUSE_BUFSIZE environment variable.
  • mld6query(8): Make "-r" option actually work. PR 51353.
  • httpd(8):
    • Add -G option to display version.
    • Fix some content type issues.
    • Fix an infinite loop in cgi processing.
    • No longer send encoding header for compressed form.
  • funopen(3): Fix memory leak. PR 51572
  • vi(1):
    • Fix memory leaks in vi when resizing. PR 50092.
    • Fix the script command of vi(1). PR 50484.
    • Fix > 1024 char lines in script.
  • zic(8): Backport changes from newer tzcode to allow proper parsing of newer tzdata files.
  • /etc/rc.d/rtadvd: Don't fail to start if rtadvd's config file doesn't exist.
  • /etc/rc.subr: Speed up multiuser boot time on slow machines. PR 50046.
  • 3rd party software updates:
    • gcc(1): Update 4.8.5.
    • Lua: Update to 5.3.3
    • root.cache: Update to 2016102001.
    • tzdata: Update to 2017a.



Good time to download and test!


- wong chee tat :)

Tuesday, March 21, 2017

I missed eating my Fish Dippers




I missed eating my Fish Dippers...



- Pic from MacDonald's Singapore


- wong chee tat :)

Friday, February 24, 2017

pfSense 2.3.3 RELEASE Now Available!

pfSense 2.3.3 RELEASE Now Available!

We are happy to announce the release of pfSense® software version 2.3.3!
This is a maintenance release in the 2.3.x series, bringing numerous stability and bug fixes, fixes for a handful of security issues in the GUI, and a handful of new features. The full list of changes is on the 2.3.3 New Features and Changes page, including a list of FreeBSD and internal security advisories addressed by this release.
This release includes fixes for 101 bugs, 14 Features, and 3 Todo items.
If you haven’t yet caught up on the changes in 2.3.x, check out the Features and Highlights video. Past blog posts have covered some of the changes, such as the performance improvements from tryforward, and thewebGUI update.

Upgrade Considerations

As always, you can upgrade from any prior version directly to 2.3.3. The Upgrade Guide covers everything you’ll need to know for upgrading in general.  There are a few areas where additional caution should be exercised with this upgrade if upgrading from 2.2.x or an earlier release, all noted in the 2.3 Upgrade Guide.

Known Regressions

While, nearly all of the common regressions between 2.2.6 and 2.3-RELEASE have been fixed in subsequent releases, the following still exist:
  • IPsec IPComp does not work. This is disabled by default. However in 2.3.1, it is automatically not enabled to avoid encountering this problem. Bug 6167
  • IGMP Proxy does not work with VLAN interfaces, and possibly other edge cases. Bug 6099. This is a little-used component. If you’re not sure what it is, you’re not using it. This has been fixed on our 2.4 development branch.
  • Those using IPsec and OpenBGPD may have non-functional IPsec unless OpenBGPD is removed. Bug 6223

Packages

Compared to pfSense 2.2.x, the list of available packages in pfSense 2.3.x has been significantly trimmed.  We have removed packages that have been deprecated upstream, no longer have an active maintainer, or were never stable. A few have yet to be converted for Bootstrap and may return if converted. See the 2.3 Removed Packages list for details.  pfSense 2.3.3 does bring back tinc (Mesh VPN), LCDproc, TFTP Server, and a new package “cellular” for use with some Huawei model 3G/4G cellular cards. Also noteworthy in case you missed it is the recently added ACME package for use with Let’s Encrypt which is available on 2.3.2-p1, 2.3.3, and 2.4.

pfSense software is Open Source

For those who wish to review the source code in full detail, the changes are all publicly available in three repositories on Github. 2.3.3 is built from the RELENG_2_3_3 branch of each repository.
Main repository – the web GUI, back end configuration code, and build tools.
FreeBSD source – the source code, with patches of the FreeBSD 10.3 base.
FreeBSD ports – the FreeBSD ports used.

Download

Downloads are available on the mirrors as usual.
Downloads for New Installs and Upgrades to Existing Systems – note it’s usually easier to just use the auto-update functionality, in which case you don’t need to download anything from here. Check the Firmware Updates page for details.

Supporting the Project

Our efforts are made possible by the support our customers and the community. You can support our efforts via one or more of the following.
  • pfSense Store –  official hardware, apparel and pre-loaded USB sticks direct from the source.  Ourpre-installed appliances are the fast, easy way to get up and running with a fully-optimized system. All are now shipping with 2.3 release installed.
  • Gold subscription – Immediate access to past hang out recordings as well as the latest version of the book after logging in to the members area.
  • Commercial Support – Purchasing support from us provides you with direct access to the pfSense team.
  • Professional Services – For more involved and complex projects outside the scope of support, our most senior engineers are available under professional services.

I hope I have time to explore it!


- wong chee tat :)

Monday, February 6, 2017

Apache OpenOffice 4.1.3 - Known Issues

Apache OpenOffice 4.1.3 - Known Issues

Known Issues

  • For macOS users:
    • Apache OpenOffice 4.1.3 will be flagged by the Gatekeeper facility in Mac OS X. This is a feature to help guard against malware on recent Mac OS X systems.
      • For Mac OS X up to 10.11 "El Capitan": There is a procedure laid out at the following link to allow applications not installed from the Mac App store to run. See the Mac support article.
      • For Mac OS X 10.12 "Sierra": In Finder, Control-click or right click the icon of the app. Select Open from the top of contextual menu that appears. Click Open in the dialog box. If prompted, enter an administrator name and password.This is needed just the first time you launch Apache OpenOffice.
    • Due to a known bug in Oracle Java installations of Apache OpenOffice on OSX that do not have the legacy Apple Java 6 installed will not be able to recognize Oracle Java 7, 8, and possibly 9. The work around until the Java bug is fixed is to install the legacy version of Apple Java from the following link: Legacy Apple Java 6. This will allow the portions of AOO that require Java to run properly.
  • For Windows users:
    • Apache OpenOffice 4.1.3 supports Java 8, which is the recommended configuration; but (especially on 64-bit Windows) you might receive warnings about the Java version being defective. In that case, download and install the Microsoft Visual C++ 2010 Redistributable Package.
  • For developers:
    • The source package of OpenOffice 4.1.3 will not build on 32-bit versions of Ubuntu 14.04 and similar distributions. The source fails to build in main/svl with this error: undefined reference to `__stack_chk_fail'. This can be worked around by copying and pasting the command that fails and running it manually with "-lc" appended (as the missing __stack_chk_fail symbol is present in libc, but the linker doesn't search there).
    • The OpenOffice SDK won't build with Java 8. Either build with --disable-odk or see the dev list archives for possible solutions.


Installed openoffice 4.1.3 on my machine.


- wong chee tat :)

Sunday, February 5, 2017

Release Notes for Apache OpenOffice 4.1.3

Release Notes for Apache OpenOffice 4.1.3


General Remarks

Apache OpenOffice 4.1.3 is a maintenance release incorporating important bug fixes, security fixes, updated dictionaries, and build fixes. All users of Apache OpenOffice 4.1.2 or earlier are advised to upgrade. You can download Apache OpenOffice 4.1.3 at the usual place. Please review these Release Notes to learn what is new in this version as well as important remarks concerning known issues and their workarounds.

Improvements/Enhancements

Bug Fixes

  • BZ 126622 Base 4.1.2 does not open Tables and Queries in Mac OSX. This 4.1.2 regression, fixed in 4.1.3, affected all database tables and queries on Mac OS X
  • The fix for security issue CVE-2016-1513,  previously only provided in source code and as a hotfix patch, is incorporated in the 4.1.3 binary distribution. See BZ 127045 Enforce Polygon API contracts at run-time.
  • BZ 127100 Make NSIS 3.* a build requirement for building Windows installers
For a complete overview of all resolved issues please see the list in Bugzilla.

Language Support

  • OpenOffice 4.1.3 supports the same languages as the previous releases.
  • No translations were updated.
  • The following dictionaries were updated:
English (en_GB)English (en_US)

German (de)German Austria (de_AT)German Switzerland (de_CH)
Dutch (nl)French (fr)Italian (it)
Spanish (es)Romanian (ro)Russian (ru)
Khmer (km)Scottish Gaelic (gd)Basque (eu)
Slovanian (sl)Norwegian (no)Swedish (sv)
Portuguese European (pt_PT)Catalan (ca_XV)

For a complete list of available languages and language packs see the download webpage (click the language drop-down-box)

Platform Support

Binaries are still provided for the same platforms as for the previous OpenOffice 4.x releases:
  • Windows
  • Mac OS X
  • Linux 32-bit (RPM and DEB)
  • Linux 64-bit (RPM and DEB)

Known Issues

  • For macOS users:
    • Apache OpenOffice 4.1.3 will be flagged by the Gatekeeper facility in Mac OS X. This is a feature to help guard against malware on recent Mac OS X systems.
      • For Mac OS X up to 10.11 "El Capitan": There is a procedure laid out at the following link to allow applications not installed from the Mac App store to run. See the Mac support article.
      • For Mac OS X 10.12 "Sierra": In Finder, Control-click or right click the icon of the app. Select Open from the top of contextual menu that appears. Click Open in the dialog box. If prompted, enter an administrator name and password.This is needed just the first time you launch Apache OpenOffice.
    • Due to a known bug in Oracle Java installations of Apache OpenOffice on OSX that do not have the legacy Apple Java 6 installed will not be able to recognize Oracle Java 7, 8, and possibly 9. The work around until the Java bug is fixed is to install the legacy version of Apple Java from the following link: Legacy Apple Java 6. This will allow the portions of AOO that require Java to run properly.
  • For Windows users:
    • Apache OpenOffice 4.1.3 supports Java 8, which is the recommended configuration; but (especially on 64-bit Windows) you might receive warnings about the Java version being defective. In that case, download and install the Microsoft Visual C++ 2010 Redistributable Package.
  • For developers:
    • The source package of OpenOffice 4.1.3 will not build on 32-bit versions of Ubuntu 14.04 and similar distributions. The source fails to build in main/svl with this error: undefined reference to `__stack_chk_fail'. This can be worked around by copying and pasting the command that fails and running it manually with "-lc" appended (as the missing __stack_chk_fail symbol is present in libc, but the linker doesn't search there).
    • The OpenOffice SDK won't build with Java 8. Either build with --disable-odk or see the dev list archives for possible solutions.

Openoffice 4.1.3 already available for download from 12 Oct 2016. I need to find some time to upgrade from 4.0



- wong chee tat :)


Monday, January 23, 2017

8u121 Update Release Notes

8u121 Update Release Notes

January 17, 2017



Java™ SE Development Kit 8, Update 121 (JDK 8u121)

The full version string for this update release is 1.8.0_121-b13 (where "b" means "build"). The version number is 8u121.

IANA Data 2016i

JDK 8u121 contains IANA time zone data version 2016i. For more information, refer to Timezone Data Versions in the JRE Software.

Security Baselines

The security baselines for the Java Runtime Environment (JRE) at the time of the release of JDK 8u121 are specified in the following table:
JRE Family VersionJRE Security Baseline
(Full Version String)
81.8.0_121-b13
71.7.0_131-b12
61.6.0_141-b12

JRE Expiration Date

The JRE expires whenever a new release with security vulnerability fixes becomes available. Critical patch updates, which contain security vulnerability fixes, are announced one year in advance on Critical Patch Updates, Security Alerts and Third Party Bulletin. This JRE (version 8u121) will expire with the release of the next critical patch update scheduled for April 18, 2017.
For systems unable to reach the Oracle Servers, a secondary mechanism expires this JRE (version 8u121) on May 18, 2017. After either condition is met (new release becoming available or expiration date reached), the JRE will provide additional warnings and reminders to users to update to the newer version. For more information, see JRE Expiration Date.


Notes


core-libs/javax.naming
Improved protection for JNDI remote class loading
Remote class loading via JNDI object factories stored in naming and directory services is disabled by default. To enable remote class loading by the RMI Registry or COS Naming service provider, set the following system property to the string "true", as appropriate:
com.sun.jndi.rmi.object.trustURLCodebase
    com.sun.jndi.cosnaming.object.trustURLCodebase
JDK-8158997 (not public)


security-libs/java.security
jarsigner -verbose -verify should print the algorithms used to sign the jar
The jarsigner tool has been enhanced to show details of the algorithms and keys used to generate a signed JAR file and will also provide an indication if any of them are considered weak.

Specifically, when "jarsigner -verify -verbose filename.jar" is called, a separate section is printed out showing information of the signature and timestamp (if it exists) inside the signed JAR file, even if it is treated as unsigned for various reasons. If any algorithm or key used is considered weak, as specified in the Security property, jdk.jar.disabledAlgorithms, it will be labeled with "(weak)".

For example:
- Signed by "CN=weak_signer"
   Digest algorithm: MD2 (weak) 
   Signature algorithm: MD2withRSA (weak), 512-bit key (weak)
 Timestamped by "CN=strong_tsa" on Mon Sep 26 08:59:39 CST 2016
   Timestamp digest algorithm: SHA-256 
   Timestamp signature algorithm: SHA256withRSA, 2048-bit key 
See JDK-8163304 


New Features


core-libs/java.io:serialization
Serialization Filter Configuration
Serialization Filtering introduces a new mechanism which allows incoming streams of object-serialization data to be filtered in order to improve both security and robustness. Every ObjectInputStream applies a filter, if configured, to the stream contents during deserialization. Filters are set using either a system property or a configured security property. The value of the "jdk.serialFilter" patterns are described in JEP 290 Serialization Filtering and in /lib/security/java.security. Filter actions are logged to the 'java.io.serialization' logger, if enabled. 
See JDK-8155760


core-libs/java.rmi
RMI Better constraint checking
RMI Registry and Distributed Garbage Collection use the mechanisms of JEP 290 Serialization Filtering to improve service robustness.
RMI Registry and DGC implement built-in white-list filters for the typical classes expected to be used with each service.
Additional filter patterns can be configured using either a system property or a security property. The "sun.rmi.registry.registryFilter" and "sun.rmi.transport.dgcFilter" property pattern syntax is described in JEP 290 and in /lib/security/java.security.
JDK-8156802 (not public)


security-libs
Add mechanism to allow non-default root CAs to not be subject to algorithm restrictions
*New certpath constraint: jdkCA*
In the java.security file, an additional constraint named "jdkCA" is added to thejdk.certpath.disabledAlgorithms property. This constraint prohibits the specified algorithm only if the algorithm is used in a certificate chain that terminates at a marked trust anchor in thelib/security/cacerts keystore. If the jdkCA constraint is not set, then all chains using the specified algorithm are restricted. jdkCA may only be used once in a DisabledAlgorithm expression.

Example: To apply this constraint to SHA-1 certificates, include the following: SHA1 jdkCA
See JDK-8140422


Changes


security-libs/javax.xml.crypto
Increase the minimum key length to 1024 for XML Signatures
The secure validation mode of the XML Signature implementation has been enhanced to restrict RSA and DSA keys less than 1024 bits by default as they are no longer secure enough for digital signatures. Additionally, a new security property namedjdk.xml.dsig.SecureValidationPolicy has been added to the java.security file and can be used to control the different restrictions enforced when the secure validation mode is enabled.

The secure validation mode is enabled either by setting the xml signature propertyorg.jcp.xml.dsig.secureValidation to true with thejavax.xml.crypto.XMLCryptoContext.setProperty method, or by running the code with aSecurityManager.

If an XML Signature is generated or validated with a weak RSA or DSA key, an XMLSignatureException will be thrown with the message, "RSA keys less than 1024 bits are forbidden when secure validation is enabled" or "DSA keys less than 1024 bits are forbidden when secure validation is enabled."
JDK-8140353 (not public)


docs/release_notes
Restrict certificates with DSA keys less than 1024 bits.
DSA keys less than 1024 bits are not strong enough and should be restricted in certification path building and validation. Accordingly, DSA keys less than 1024 bits have been deactivated by default by adding "DSA keySize < 1024" to the "jdk.certpath.disabledAlgorithms" security property. Applications can update this restriction in the security property ("jdk.certpath.disabledAlgorithms") and permit smaller key sizes if really needed (for example, "DSA keySize < 768").
JDK-8139565 (not public)


security-libs
More checks added to DER encoding parsing code
More checks are added to the DER encoding parsing code to catch various encoding errors. In addition, signatures which contain constructed indefinite length encoding will now lead to IOException during parsing. Note that signatures generated using JDK default providers are not affected by this change.
JDK-8168714 (not public)


core-libs/java.net
Additional access restrictions for URLClassLoader.newInstance
Class loaders created by the java.net.URLClassLoader.newInstance methods can be used to load classes from a list of given URLs. If the calling code does not have access to one or more of the URLs and the URL artifacts that can be accessed do not contain the required class, then a ClassNotFoundException, or similar, will be thrown. Previously, a SecurityException would have been thrown when access to a URL was denied. If required to revert to the old behavior, this change can be disabled by setting thejdk.net.URLClassPath.disableRestrictedPermissions system property.
JDK-8151934 (not public)


core-libs/java.util.logging
A new configurable property in logging.properties java.util.logging.FileHandler.maxLocks
A new "java.util.logging.FileHandler.maxLocks" configurable property is added tojava.util.logging.FileHandler

This new logging property can be defined in the logging configuration file and makes it possible to configure the maximum number of concurrent log file locks a FileHandler can handle. The default value is 100. 

In a highly concurrent environment where multiple (more than 101) standalone client applications are using the JDK Logging API with FileHandler simultaneously, it may happen that the default limit of 100 is reached, resulting in a failure to acquire FileHandler file locks and causing an IO Exception to be thrown. In such a case, the new logging property can be used to increase the maximum number of locks before deploying the application. 

If not overridden, the default value of maxLocks (100) remains unchanged. Seejava.util.logging.LogManager and java.util.logging.FileHandler API documentation for more details. 
See JDK-8153955
 
 

Bug Fixes


The following are some of the notable bug fixes included in this release: 

client-libs/javax.swing
Trackpad scrolling of text on OS X 10.12 Sierra is very fast
The MouseWheelEvent.getWheelRotation() method returned rounded native NSEvent deltaX/Y events on Mac OS X. The latest macOS Sierra 10.12 produces very small NSEvent deltaX/Y values so rounding and summing them leads to the huge value returned from theMouseWheelEvent.getWheelRotation(). The JDK-8166591 fix accumulates NSEvent deltaX/Y and the MouseWheelEvent.getWheelRotation() method returns non-zero values only when the accumulated value exceeds a threshold and zero value. This is compliant with theMouseWheelEvent.getWheelRotation() specification(https://docs.oracle.com/javase/8/docs/api/java/awt/event/MouseWheelEvent.html#getWheelRotation):

"Returns the number of "clicks" the mouse wheel was rotated, as an integer. A partial rotation may occur if the mouse supports a high-resolution wheel. In this case, the method returns zero until a full "click" has been accumulated."

For the precise wheel rotation values, use the MouseWheelEvent.getPreciseWheelRotation()method instead.
See JDK-8166591

This release also contains fixes for security vulnerabilities described in the Oracle Java SE Critical Patch Update Advisory. For a more complete list of the bug fixes included in this release, see theJDK 8u121 Bug Fixes page.


Known Issues


deploy/packager
javapackager and fx:deploy bundle the whole JDK instead of JRE
There is a known bug in the Java Packager for Mac where the entire JDK may be bundled with the application bundle resulting in an unusually large bundle. The work around is to use the bundler option -Bruntime option. For example: -Bruntime=JavaAppletPlugin.plugin sets where theJavaAppletPlugin.plugin for the desired JRE to bundle is located in the current directory.
See JDK-8166835

install/install
Java Installation will fail for non-admin users with UAC off
The Java installation on Windows will fail without warning or prompting, for non-admin users with User Access Control (UAC) disabled. The installer will leave a directory, jds<number>.tmp, in the %TEMP% directory.
JDK-8161460 (not public)




- wong chee tat :)