update changelogs

pull/311/head
Ad Schellevis 3 years ago
parent 51bd72f0a1
commit a1c988845c

@ -8,7 +8,7 @@ Community Edition
:width: 600px
:align: center
As of January 2015 there have been *195* releases leading to the latest version *21.1*
As of January 2015 there have been *196* releases leading to the latest version *21.1.1*
named "Marvelous Meerkat".

@ -179,7 +179,7 @@ Here are the full patch notes:
* src: microarchitectural Data Sampling (MDS) mitigation `[5] <https://www.freebsd.org/security/advisories/FreeBSD-SA-19:07.mds.asc>`__
* ports: ca_root_nss 3.44
* ports: php 7.2.18 `[6] <https://www.php.net/ChangeLog-7.php#7.2.18>`__
* ports: sqlite 3.28.0 `[7] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.28.0 `[7] <https://sqlite.org/releaselog/3_28_0.html>`__
* ports: strongswan custom XAuth generic patch removed
@ -275,7 +275,7 @@ Without further ado, here are the full patch notes:
* ports: perl 5.28.2 `[4] <https://perldoc.pl/5.28.2/perldelta>`__
* ports: py-yaml 5.1 `[5] <https://github.com/yaml/pyyaml/blob/master/CHANGES>`__
* ports: suricata 4.1.4 `[6] <https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/>`__
* ports: sqlite 3.27.2 `[7] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.27.2 `[7] <https://sqlite.org/releaselog/3_27_1.html>`__
@ -625,7 +625,7 @@ Here are the full patch notes:
* ports: libressl 2.8.3 `[9] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.8.3-relnotes.txt>`__
* ports: openvpn 2.4.7 `[10] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24>`__
* ports: pam_opnsense manual page addition
* ports: sqlite 3.27.1 `[11] <https://www.sqlite.org/releaselog/3_27_1.html>`__
* ports: sqlite 3.27.1 `[11] <https://sqlite.org/releaselog/3_27_1.html>`__
* ports: squid forgery check avoidance `[12] <https://github.com/opnsense/ports/issues/66>`__
* ports: strongswan 5.7.2 `[13] <https://wiki.strongswan.org/versions/72>`__
* ports: unbound 1.9.0 `[14] <https://nlnetlabs.nl/projects/unbound/download/>`__
@ -934,7 +934,7 @@ Here are the full changes against version 18.7.10:
* ports: krb5 1.17 `[8] <https://web.mit.edu/kerberos/krb5-1.17/>`__
* ports: php 7.1.26 `[9] <https://php.net/ChangeLog-7.php#7.1.26>`__
* ports: sudo 1.8.27 `[10] <https://www.sudo.ws/stable.html#1.8.27>`__
* ports: perl 5.28.1 `[11] <https://metacpan.org/changes/release/SHAY/perl-5.28.1>`__
* ports: perl 5.28.1 `[11] <https://perldoc.perl.org/5.28.1/perldelta>`__
* ports: suricata netmap forward-compatibility patch (contributed by Sunny Valley Networks)
Known issues and limitations:

@ -216,7 +216,7 @@ Here are the full patch notes:
* ports: curl 7.67.0 `[8] <https://curl.haxx.se/changes.html>`__
* ports: libressl 3.0.2 `[9] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.0.2-relnotes.txt>`__
* ports: openvpn 2.4.8 `[10] <https://github.com/OpenVPN/openvpn/blob/release/2.4/Changes.rst#version-248>`__
* ports: perl 5.30.1 `[11] <https://metacpan.org/pod/release/SHAY/perl-5.30.1/pod/perldelta.pod>`__
* ports: perl 5.30.1 `[11] <https://perldoc.perl.org/5.30.1/perldelta>`__
* ports: phalcon 3.4.5 `[12] <https://github.com/phalcon/cphalcon/releases/tag/v3.4.5>`__
* ports: sqlite 3.30.1 `[13] <https://sqlite.org/releaselog/3_30_1.html>`__
* ports: squid 4.9 `[14] <https://github.com/squid-cache/squid/blob/master/ChangeLog>`__
@ -438,7 +438,7 @@ Here is the full list of changes:
* ports: hostapd 2.9 `[15] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: nghttp2 1.39.2 `[16] <https://github.com/nghttp2/nghttp2/releases/tag/v1.39.2>`__
* ports: openldap 2.4.48 `[17] <https://www.openldap.org/software/release/changes.html>`__
* ports: perl 5.30.0 `[18] <https://metacpan.org/pod/release/XSAWYERX/perl-5.30.0/pod/perldelta.pod>`__
* ports: perl 5.30.0 `[18] <https://perldoc.perl.org/5.30.0/perldelta>`__
* ports: php 7.2.21 `[19] <https://www.php.net/ChangeLog-7.php#7.2.21>`__
* ports: py-openssl 19.0.0 `[20] <https://www.pyopenssl.org/en/stable/changelog.html>`__
* ports: syslog-ng 3.22.1 `[21] <https://github.com/balabit/syslog-ng/releases/tag/syslog-ng-3.22.1>`__

@ -59,7 +59,7 @@ Here are the full patch notes:
* ports: monit 5.27.0 `[8] <https://mmonit.com/monit/changes/>`__
* ports: php 7.3.20 `[9] <https://www.php.net/ChangeLog-7.php#7.3.20>`__
* ports: python 3.7.8 `[10] <https://www.python.org/downloads/release/python-378/>`__
* ports: sqlite 3.32.3 `[11] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.3 `[11] <https://sqlite.org/releaselog/3_32_3.html>`__
* ports: syslog-ng 3.27.1 `[12] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.27.1>`__
A hotfix release was issued as 20.1.9_1:
@ -114,10 +114,10 @@ Here are the full patch notes:
* ports: krb5 1.18.2 `[11] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: ntp 4.2.8p15 `[12] <http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities>`__
* ports: pcre 8.44 `[13] <https://www.pcre.org/original/changelog.txt>`__
* ports: perl 5.30.3 `[14] <https://perldoc.perl.org/5.30.3/perldelta.html>`__
* ports: perl 5.30.3 `[14] <https://perldoc.perl.org/5.30.3/perldelta>`__
* ports: php 7.3.19 `[15] <https://www.php.net/ChangeLog-7.php#7.3.19>`__
* ports: python CVE-2019-18348 and CVE-2020-8492
* ports: sqlite 3.32.2 `[16] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.2 `[16] <https://sqlite.org/releaselog/3_32_2.html>`__
* ports: sudo 1.9.1 `[17] <https://www.sudo.ws/stable.html#1.9.1>`__
* ports: unbound 1.10.1 `[18] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-10-1>`__
@ -192,7 +192,7 @@ Quick update as planned. Here are the full patch notes:
* ports: openssl 1.1.1g `[3] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: py-yaml 5.3.1 `[4] <https://raw.githubusercontent.com/yaml/pyyaml/master/CHANGES>`__
* ports: radvd 2.18 `[5] <http://www.litech.org/radvd/CHANGES.txt>`__
* ports: sqlite 3.31.1 `[6] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.31.1 `[6] <https://sqlite.org/releaselog/3_31_1.html>`__
* ports: squid 4.11 `[7] <http://ftp.meisei-u.ac.jp/mirror/squid/squid-4.11-RELEASENOTES.html>`__
* ports: suricata 4.1.8 `[8] <https://suricata-ids.org/2020/04/28/suricata-4-1-8-released/>`__
@ -303,7 +303,7 @@ Here are the full patch notes:
* ports: krb5 1.18 `[16] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: openssh 8.2p1 `[17] <https://www.openssh.com/txt/release-8.2>`__
* ports: openssl 1.1.1f `[18] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: perl 5.30.2 `[19] <https://metacpan.org/pod/release/SHAY/perl-5.30.2/pod/perldelta.pod>`__
* ports: perl 5.30.2 `[19] <https://perldoc.perl.org/5.30.2/perldelta>`__
* ports: php 7.2.29 `[20] <https://www.php.net/ChangeLog-7.php#7.2.29>`__
* ports: python 3.7.7 `[21] <https://www.python.org/downloads/release/python-377/>`__
* ports: strongswan 5.8.3 `[22] <https://wiki.strongswan.org/versions/76>`__

@ -126,7 +126,7 @@ Here are the full patch notes:
* ports: openssl 1.1.1i `[9] <https://www.openssl.org/news/secadv/20201208.txt>`__
* ports: pcre2 10.36 `[10] <https://www.pcre.org/changelog.txt>`__
* ports: sudo 1.9.4 `[11] <https://www.sudo.ws/stable.html#1.9.4>`__
* ports: sqlite 3.34.0 `[12] <https://sqlite.org/changes.html>`__
* ports: sqlite 3.34.0 `[12] <https://sqlite.org/releaselog/3_34_0.html>`__
* ports: unbound 1.13.0 `[13] <https://nlnetlabs.nl/projects/unbound/download/>`__
A hotfix release was issued as 20.7.7_1:
@ -390,7 +390,7 @@ Here are the full patch notes:
* ports: openldap 2.4.51 `[7] <https://www.openldap.org/software/release/changes.html>`__
* ports: php 7.3.21 `[8] <https://www.php.net/ChangeLog-7.php#7.3.21>`__
* ports: python 3.7.9 `[9] <https://www.python.org/downloads/release/python-379/>`__
* ports: sqlite 3.33.0 `[10] <https://sqlite.org/changes.html>`__
* ports: sqlite 3.33.0 `[10] <https://sqlite.org/releaselog/3_33_0.html>`__
* ports: squid 4.13 `[11] <http://www.squid-cache.org/Versions/v4/squid-4.13-RELEASENOTES.html>`__
* ports: syslog-ng dlsym() workaround
* ports: unbound 1.11.0 `[12] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-11-0>`__
@ -433,7 +433,7 @@ Here are the full patch notes:
* src: fix memory corruption in USB network device driver `[5] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:21.usb_net.asc>`__
* src: fix multiple vulnerabilities in sqlite3 `[6] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:22.sqlite.asc>`__
* src: fix sendmsg(2) privilege escalation `[7] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:23.sendmsg.asc>`__
* ports: perl 5.32.0 `[8] <https://metacpan.org/changes/release/XSAWYERX/perl-5.32.0>`__
* ports: perl 5.32.0 `[8] <https://perldoc.perl.org/5.32.0/perldelta>`__
* ports: squid 4.12 `[9] <http://www.squid-cache.org/Versions/v4/squid-4.12-RELEASENOTES.html>`__
@ -589,7 +589,7 @@ Here are the full patch notes against 20.1.8_1:
* ports: curl 7.71.1 `[6] <https://curl.haxx.se/changes.html>`__
* ports: php 7.3.20 `[7] <https://www.php.net/ChangeLog-7.php#7.3.20>`__
* ports: python 3.7.8 `[8] <https://www.python.org/downloads/release/python-378/>`__
* ports: sqlite 3.32.3 `[9] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.3 `[9] <https://sqlite.org/releaselog/3_32_3.html>`__
* ports: suricata 5.0.3 `[10] <https://suricata-ids.org/2020/04/28/suricata-5-0-3-released/>`__
Known issues and limitations:

@ -377,7 +377,7 @@ Here is the full list of changes:
* ports: bsdinstaller 2.3 no longer uses cpdup utility, plus log collection
and SONAME fixes
* ports: updated to pkg 1.5.2, phalcon 2.0.0, dnsmasq 2.72_1 `[4] <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3294>`__
* ports: perl5 is now installed by default (5.18)
* ports: Perl is now installed by default (5.18)
* development: OpenSSL and LibreSSL branches have been merged for a simpler
build experience and smaller release times
* development: the package sets are now always kept as a single archive that

@ -36,7 +36,7 @@ tools. Please see the full patch notes for details and references:
* base: improved iconv(3) UTF-7 support `[3] <https://www.freebsd.org/security/advisories/FreeBSD-EN-15:10.iconv.asc>`__
* base: inconsistency between locale and rune locale states `[4] <https://www.freebsd.org/security/advisories/FreeBSD-EN-15:09.xlocale.asc>`__
* notable ports updates: phalcon 2.0.3 `[5] <https://github.com/phalcon/cphalcon/releases/tag/phalcon-v2.0.3>`__ , curl 7.43.0_2 `[6] <https://curl.haxx.se/changes.html>`__ ,
openssh 6.8p1_8, python 2.7.10 `[7] <https://hg.python.org/cpython/raw-file/15c95b7d81dc/Misc/NEWS>`__ , perl 5.20.2_5 `[8] <http://perldoc.perl.org/perl5202delta.html>`__ , ntp 4.2.8p3 `[9] <http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ChangeLog-stable>`__ ,
openssh 6.8p1_8, python 2.7.10 `[7] <https://hg.python.org/cpython/raw-file/15c95b7d81dc/Misc/NEWS>`__ , perl 5.20.2_5 `[8] <https://perldoc.perl.org/5.20.2/perldelta>`__ , ntp 4.2.8p3 `[9] <http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ChangeLog-stable>`__ ,
libxml2 2.9.2_3 `[10] <https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-1819>`__ , openldap24-server 2.4.41 `[11] <https://www.openldap.org/software/release/changes.html>`__
* opnsense-update: will no longer try to reinstall the istalled version
after a fresh installation
@ -1142,7 +1142,7 @@ tools. Please see the full patch notes for details and references:
* base: improved iconv(3) UTF-7 support `[3] <https://www.freebsd.org/security/advisories/FreeBSD-EN-15:10.iconv.asc>`__
* base: inconsistency between locale and rune locale states `[4] <https://www.freebsd.org/security/advisories/FreeBSD-EN-15:09.xlocale.asc>`__
* notable ports updates: phalcon 2.0.3 `[5] <https://github.com/phalcon/cphalcon/releases/tag/phalcon-v2.0.3>`__ , curl 7.43.0_2 `[6] <https://curl.haxx.se/changes.html>`__ ,
openssh 6.8p1_8, python 2.7.10 `[7] <https://hg.python.org/cpython/raw-file/15c95b7d81dc/Misc/NEWS>`__ , perl 5.20.2_5 `[8] <http://perldoc.perl.org/perl5202delta.html>`__ , ntp 4.2.8p3 `[9] <http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ChangeLog-stable>`__ ,
openssh 6.8p1_8, python 2.7.10 `[7] <https://hg.python.org/cpython/raw-file/15c95b7d81dc/Misc/NEWS>`__ , perl 5.20.2_5 `[8] <https://perldoc.perl.org/5.20.2/perldelta>`__ , ntp 4.2.8p3 `[9] <http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ChangeLog-stable>`__ ,
libxml2 2.9.2_3 `[10] <https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-1819>`__ , openldap24-server 2.4.41 `[11] <https://www.openldap.org/software/release/changes.html>`__
* opnsense-update: will no longer try to reinstall the istalled version
after a fresh installation

@ -56,7 +56,7 @@ Until then, here are the full patch notes:
* libressl: avoid possible side-channel leak of ECDSA private keys
when signing `[1] <https://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/016_libcrypto.patch.sig>`__
* ports: bind 9.10.4-P5 `[2] <https://deepthought.isc.org/article/AA-01447/0/BIND-9.10.4-P5-Release-Notes.html>`__
* ports: perl5 5.24.1 `[3] <http://search.cpan.org/dist/perl-5.24.1/pod/perldelta.pod>`__
* ports: perl 5.24.1 `[3] <https://perldoc.perl.org/5.24.1/perldelta>`__
* ports: sqlite 3.16.2 `[4] <https://sqlite.org/releaselog/3_16_2.html>`__
* ports: openssh-portable 7.4p1 `[5] <https://www.openssh.com/txt/release-7.4>`__
* ports: sudo 1.8.19p2 `[6] <https://www.sudo.ws/stable.html#1.8.19p2>`__
@ -99,7 +99,7 @@ Here are the full patch notes:
* ports: ca_root_nss 3.28
* ports: squid 3.5.23 `[2] <http://ftp.meisei-u.ac.jp/mirror/squid/squid-3.5-ChangeLog.txt>`__
* ports: python 2.7.13 `[3] <https://hg.python.org/cpython/raw-file/v2.7.13/Misc/NEWS>`__
* ports: perl 5.24.1-RC5 `[4] <http://search.cpan.org/~shay/perl-5.24.1-RC5/>`__
* ports: perl 5.24.1-RC5 `[4] <https://perldoc.perl.org/5.24.1/perldelta>`__
* ports: lighttpd 1.4.44 `[5] <https://www.lighttpd.net/2016/12/24/1.4.44/>`__
* ports: phalcon 3.0.3 `[6] <https://github.com/phalcon/cphalcon/releases/tag/v3.0.3>`__
* ports: heimdal 7.1.0 `[7] <https://www.h5l.org/releases.html?show=7.1>`__

@ -56,7 +56,7 @@ Here are the full patch notes:
* openvpn: normalise line endings of used certificates
* openvpn: fix config handling in GUI pages for PHP 7.1
* plugins: os-quagga 1.3.2 (contributed by Fabian Franz and Michael Muenz)
* ports: perl 5.24.2 `[1] <http://search.cpan.org/dist/perl-5.24.2/pod/perldelta.pod>`__
* ports: perl 5.24.2 `[1] <https://perldoc.perl.org/5.24.2/perldelta>`__
* ports: strongswan 5.5.3 `[2] <https://wiki.strongswan.org/versions/65>`__

@ -409,9 +409,9 @@ Here are the full patch notes:
* plugins: os-intrusion-detection-content-et-pro 1.0
* plugins: os-quagga 1.4.2 OSPF router ID support (contributed by Fabian Franz)
* ports: dnsmasq 2.78 `[1] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: kerberos 1.15.2 `[2] <https://web.mit.edu/kerberos/krb5-1.15/#announcement>`__
* ports: kerberos 1.15.2 `[2] <https://web.mit.edu/kerberos/krb5-1.15/>`__
* ports: openvpn 2.4.4 `[3] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24>`__
* ports: perl 5.24.3 `[4] <http://search.cpan.org/dist/perl-5.24.3/pod/perldelta.pod>`__
* ports: perl 5.24.3 `[4] <https://perldoc.perl.org/5.24.3/perldelta>`__
* ports: php 7.0.24 `[5] <https://php.net/ChangeLog-7.php#7.0.24>`__
* ports: python 2.7.14 `[6] <https://raw.githubusercontent.com/python/cpython/84471935e/Misc/NEWS>`__
@ -865,7 +865,7 @@ Here is the full list of changes against version 17.7-RC1:
* plugins: os-dyndns 1.1 fixes menu entry visibility
* plugins: os-quagga 1.3.2 (contributed by Fabian Franz and Michael Muenz)
* ports: php 7.0.21 `[1] <https://php.net/ChangeLog-7.php#7.0.21>`__
* ports: perl 5.24.2 `[2] <http://search.cpan.org/dist/perl-5.24.2/pod/perldelta.pod>`__
* ports: perl 5.24.2 `[2] <https://perldoc.perl.org/5.24.2/perldelta>`__
* ports: suricata 3.2.3 `[3] <https://suricata-ids.org/2017/07/13/suricata-3-2-3-available/>`__
* ports: unbound 1.6.4 `[4] <https://nlnetlabs.nl/projects/unbound/download/>`__

@ -476,7 +476,7 @@ Here are the full patch notes:
* ports: openldap 2.4.46 `[3] <https://www.openldap.org/software/release/changes.html>`__
* ports: openssh 7.7p1 `[4] <https://www.openssh.com/txt/release-7.7>`__
* ports: openvpn 2.4.6 `[5] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24>`__
* ports: perl 5.26.2 `[6] <http://search.cpan.org/~shay/perl-5.26.2/pod/perldelta.pod>`__
* ports: perl 5.26.2 `[6] <https://perldoc.perl.org/5.26.2/perldelta>`__
* ports: php 7.1.17 `[7] <https://php.net/ChangeLog-7.php#7.1.17>`__
* ports: sqlite 3.23.0 `[8] <https://sqlite.org/releaselog/3_23_0.html>`__
@ -549,7 +549,7 @@ Here are the full patch notes:
* src: timezone database information update `[4] <https://security.freebsd.org/advisories/FreeBSD-EN-18:03.tzdata.asc>`__
* ports: dnsmasq 2.79 `[5] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: openssl 1.0.2o `[6] <https://www.openssl.org/news/secadv/20180327.txt>`__
* ports: perl 5.26.1 `[7] <https://metacpan.org/pod/release/SHAY/perl-5.26.1/pod/perldelta.pod>`__
* ports: perl 5.26.1 `[7] <https://perldoc.perl.org/5.26.1/perldelta>`__
* ports: php 7.1.16 `[8] <https://php.net/ChangeLog-7.php#7.1.16>`__
* ports: squid 3.5.27 adds LDAP authentication

@ -240,8 +240,8 @@ Here are the full patch notes:
* src: fix deferred kernel loading breaks loader password `[5] <https://www.freebsd.org/security/advisories/FreeBSD-EN-18:15.loader.asc>`__
* src: fix insufficient bounds checking in bhyve(8) device model `[6] <https://www.freebsd.org/security/advisories/FreeBSD-SA-18:14.bhyve.asc>`__
* ports: lighttpd 1.4.52 `[7] <https://www.lighttpd.net/2018/11/28/1.4.52/>`__
* ports: sqlite 3.26.0 `[8] <https://www.sqlite.org/releaselog/3_26_0.html>`__
* ports: perl 5.26.3 `[9] <https://metacpan.org/pod/release/SHAY/perl-5.26.3/pod/perldelta.pod>`__
* ports: sqlite 3.26.0 `[8] <https://sqlite.org/releaselog/3_26_0.html>`__
* ports: perl 5.26.3 `[9] <https://perldoc.perl.org/5.26.3/perldelta>`__
* ports: php 7.1.25 `[10] <https://php.net/ChangeLog-7.php#7.1.25>`__
* ports: hostapd / wpa_supplicant 2.7 `[11] <http://lists.infradead.org/pipermail/hostap/2018-December/039069.html>`__
* ports: unbound 1.8.2 `[12] <https://nlnetlabs.nl/projects/unbound/download/>`__
@ -556,7 +556,7 @@ Here are the full patch notes:
* src: update re(4) driver to upstream version 1.95
* ports: libressl 2.7.4 `[1] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.7.4-relnotes.txt>`__
* ports: php 7.1.22 `[2] <https://php.net/ChangeLog-7.php#7.1.22>`__
* ports: sqlite 3.25.1 `[3] <https://www.sqlite.org/releaselog/3_25_1.html>`__
* ports: sqlite 3.25.1 `[3] <https://sqlite.org/releaselog/3_25_1.html>`__
* ports: squid 3.5.28 `[4] <http://ftp.meisei-u.ac.jp/mirror/squid/squid-3.5.28-RELEASENOTES.html>`__

@ -179,7 +179,7 @@ Here are the full patch notes:
* src: microarchitectural Data Sampling (MDS) mitigation `[5] <https://www.freebsd.org/security/advisories/FreeBSD-SA-19:07.mds.asc>`__
* ports: ca_root_nss 3.44
* ports: php 7.2.18 `[6] <https://www.php.net/ChangeLog-7.php#7.2.18>`__
* ports: sqlite 3.28.0 `[7] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.28.0 `[7] <https://sqlite.org/releaselog/3_28_0.html>`__
* ports: strongswan custom XAuth generic patch removed
@ -275,7 +275,7 @@ Without further ado, here are the full patch notes:
* ports: perl 5.28.2 `[4] <https://perldoc.pl/5.28.2/perldelta>`__
* ports: py-yaml 5.1 `[5] <https://github.com/yaml/pyyaml/blob/master/CHANGES>`__
* ports: suricata 4.1.4 `[6] <https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/>`__
* ports: sqlite 3.27.2 `[7] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.27.2 `[7] <https://sqlite.org/releaselog/3_27_1.html>`__
@ -625,7 +625,7 @@ Here are the full patch notes:
* ports: libressl 2.8.3 `[9] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.8.3-relnotes.txt>`__
* ports: openvpn 2.4.7 `[10] <https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24>`__
* ports: pam_opnsense manual page addition
* ports: sqlite 3.27.1 `[11] <https://www.sqlite.org/releaselog/3_27_1.html>`__
* ports: sqlite 3.27.1 `[11] <https://sqlite.org/releaselog/3_27_1.html>`__
* ports: squid forgery check avoidance `[12] <https://github.com/opnsense/ports/issues/66>`__
* ports: strongswan 5.7.2 `[13] <https://wiki.strongswan.org/versions/72>`__
* ports: unbound 1.9.0 `[14] <https://nlnetlabs.nl/projects/unbound/download/>`__
@ -934,7 +934,7 @@ Here are the full changes against version 18.7.10:
* ports: krb5 1.17 `[8] <https://web.mit.edu/kerberos/krb5-1.17/>`__
* ports: php 7.1.26 `[9] <https://php.net/ChangeLog-7.php#7.1.26>`__
* ports: sudo 1.8.27 `[10] <https://www.sudo.ws/stable.html#1.8.27>`__
* ports: perl 5.28.1 `[11] <https://metacpan.org/changes/release/SHAY/perl-5.28.1>`__
* ports: perl 5.28.1 `[11] <https://perldoc.perl.org/5.28.1/perldelta>`__
* ports: suricata netmap forward-compatibility patch (contributed by Sunny Valley Networks)
Known issues and limitations:

@ -216,7 +216,7 @@ Here are the full patch notes:
* ports: curl 7.67.0 `[8] <https://curl.haxx.se/changes.html>`__
* ports: libressl 3.0.2 `[9] <https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.0.2-relnotes.txt>`__
* ports: openvpn 2.4.8 `[10] <https://github.com/OpenVPN/openvpn/blob/release/2.4/Changes.rst#version-248>`__
* ports: perl 5.30.1 `[11] <https://metacpan.org/pod/release/SHAY/perl-5.30.1/pod/perldelta.pod>`__
* ports: perl 5.30.1 `[11] <https://perldoc.perl.org/5.30.1/perldelta>`__
* ports: phalcon 3.4.5 `[12] <https://github.com/phalcon/cphalcon/releases/tag/v3.4.5>`__
* ports: sqlite 3.30.1 `[13] <https://sqlite.org/releaselog/3_30_1.html>`__
* ports: squid 4.9 `[14] <https://github.com/squid-cache/squid/blob/master/ChangeLog>`__
@ -438,7 +438,7 @@ Here is the full list of changes:
* ports: hostapd 2.9 `[15] <https://w1.fi/cgit/hostap/plain/hostapd/ChangeLog>`__
* ports: nghttp2 1.39.2 `[16] <https://github.com/nghttp2/nghttp2/releases/tag/v1.39.2>`__
* ports: openldap 2.4.48 `[17] <https://www.openldap.org/software/release/changes.html>`__
* ports: perl 5.30.0 `[18] <https://metacpan.org/pod/release/XSAWYERX/perl-5.30.0/pod/perldelta.pod>`__
* ports: perl 5.30.0 `[18] <https://perldoc.perl.org/5.30.0/perldelta>`__
* ports: php 7.2.21 `[19] <https://www.php.net/ChangeLog-7.php#7.2.21>`__
* ports: py-openssl 19.0.0 `[20] <https://www.pyopenssl.org/en/stable/changelog.html>`__
* ports: syslog-ng 3.22.1 `[21] <https://github.com/balabit/syslog-ng/releases/tag/syslog-ng-3.22.1>`__

@ -59,7 +59,7 @@ Here are the full patch notes:
* ports: monit 5.27.0 `[8] <https://mmonit.com/monit/changes/>`__
* ports: php 7.3.20 `[9] <https://www.php.net/ChangeLog-7.php#7.3.20>`__
* ports: python 3.7.8 `[10] <https://www.python.org/downloads/release/python-378/>`__
* ports: sqlite 3.32.3 `[11] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.3 `[11] <https://sqlite.org/releaselog/3_32_3.html>`__
* ports: syslog-ng 3.27.1 `[12] <https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.27.1>`__
A hotfix release was issued as 20.1.9_1:
@ -114,10 +114,10 @@ Here are the full patch notes:
* ports: krb5 1.18.2 `[11] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: ntp 4.2.8p15 `[12] <http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities>`__
* ports: pcre 8.44 `[13] <https://www.pcre.org/original/changelog.txt>`__
* ports: perl 5.30.3 `[14] <https://perldoc.perl.org/5.30.3/perldelta.html>`__
* ports: perl 5.30.3 `[14] <https://perldoc.perl.org/5.30.3/perldelta>`__
* ports: php 7.3.19 `[15] <https://www.php.net/ChangeLog-7.php#7.3.19>`__
* ports: python CVE-2019-18348 and CVE-2020-8492
* ports: sqlite 3.32.2 `[16] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.2 `[16] <https://sqlite.org/releaselog/3_32_2.html>`__
* ports: sudo 1.9.1 `[17] <https://www.sudo.ws/stable.html#1.9.1>`__
* ports: unbound 1.10.1 `[18] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-10-1>`__
@ -192,7 +192,7 @@ Quick update as planned. Here are the full patch notes:
* ports: openssl 1.1.1g `[3] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: py-yaml 5.3.1 `[4] <https://raw.githubusercontent.com/yaml/pyyaml/master/CHANGES>`__
* ports: radvd 2.18 `[5] <http://www.litech.org/radvd/CHANGES.txt>`__
* ports: sqlite 3.31.1 `[6] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.31.1 `[6] <https://sqlite.org/releaselog/3_31_1.html>`__
* ports: squid 4.11 `[7] <http://ftp.meisei-u.ac.jp/mirror/squid/squid-4.11-RELEASENOTES.html>`__
* ports: suricata 4.1.8 `[8] <https://suricata-ids.org/2020/04/28/suricata-4-1-8-released/>`__
@ -303,7 +303,7 @@ Here are the full patch notes:
* ports: krb5 1.18 `[16] <https://web.mit.edu/kerberos/krb5-1.18/>`__
* ports: openssh 8.2p1 `[17] <https://www.openssh.com/txt/release-8.2>`__
* ports: openssl 1.1.1f `[18] <https://www.openssl.org/news/openssl-1.1.1-notes.html>`__
* ports: perl 5.30.2 `[19] <https://metacpan.org/pod/release/SHAY/perl-5.30.2/pod/perldelta.pod>`__
* ports: perl 5.30.2 `[19] <https://perldoc.perl.org/5.30.2/perldelta>`__
* ports: php 7.2.29 `[20] <https://www.php.net/ChangeLog-7.php#7.2.29>`__
* ports: python 3.7.7 `[21] <https://www.python.org/downloads/release/python-377/>`__
* ports: strongswan 5.8.3 `[22] <https://wiki.strongswan.org/versions/76>`__

@ -126,7 +126,7 @@ Here are the full patch notes:
* ports: openssl 1.1.1i `[9] <https://www.openssl.org/news/secadv/20201208.txt>`__
* ports: pcre2 10.36 `[10] <https://www.pcre.org/changelog.txt>`__
* ports: sudo 1.9.4 `[11] <https://www.sudo.ws/stable.html#1.9.4>`__
* ports: sqlite 3.34.0 `[12] <https://sqlite.org/changes.html>`__
* ports: sqlite 3.34.0 `[12] <https://sqlite.org/releaselog/3_34_0.html>`__
* ports: unbound 1.13.0 `[13] <https://nlnetlabs.nl/projects/unbound/download/>`__
A hotfix release was issued as 20.7.7_1:
@ -390,7 +390,7 @@ Here are the full patch notes:
* ports: openldap 2.4.51 `[7] <https://www.openldap.org/software/release/changes.html>`__
* ports: php 7.3.21 `[8] <https://www.php.net/ChangeLog-7.php#7.3.21>`__
* ports: python 3.7.9 `[9] <https://www.python.org/downloads/release/python-379/>`__
* ports: sqlite 3.33.0 `[10] <https://sqlite.org/changes.html>`__
* ports: sqlite 3.33.0 `[10] <https://sqlite.org/releaselog/3_33_0.html>`__
* ports: squid 4.13 `[11] <http://www.squid-cache.org/Versions/v4/squid-4.13-RELEASENOTES.html>`__
* ports: syslog-ng dlsym() workaround
* ports: unbound 1.11.0 `[12] <https://nlnetlabs.nl/projects/unbound/download/#unbound-1-11-0>`__
@ -433,7 +433,7 @@ Here are the full patch notes:
* src: fix memory corruption in USB network device driver `[5] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:21.usb_net.asc>`__
* src: fix multiple vulnerabilities in sqlite3 `[6] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:22.sqlite.asc>`__
* src: fix sendmsg(2) privilege escalation `[7] <https://www.freebsd.org/security/advisories/FreeBSD-SA-20:23.sendmsg.asc>`__
* ports: perl 5.32.0 `[8] <https://metacpan.org/changes/release/XSAWYERX/perl-5.32.0>`__
* ports: perl 5.32.0 `[8] <https://perldoc.perl.org/5.32.0/perldelta>`__
* ports: squid 4.12 `[9] <http://www.squid-cache.org/Versions/v4/squid-4.12-RELEASENOTES.html>`__
@ -589,7 +589,7 @@ Here are the full patch notes against 20.1.8_1:
* ports: curl 7.71.1 `[6] <https://curl.haxx.se/changes.html>`__
* ports: php 7.3.20 `[7] <https://www.php.net/ChangeLog-7.php#7.3.20>`__
* ports: python 3.7.8 `[8] <https://www.python.org/downloads/release/python-378/>`__
* ports: sqlite 3.32.3 `[9] <https://www.sqlite.org/changes.html>`__
* ports: sqlite 3.32.3 `[9] <https://sqlite.org/releaselog/3_32_3.html>`__
* ports: suricata 5.0.3 `[10] <https://suricata-ids.org/2020/04/28/suricata-5-0-3-released/>`__
Known issues and limitations:

@ -38,6 +38,60 @@ can be found below as well.
* Full mirror list: https://opnsense.org/download/
--------------------------------------------------------------------------
21.1.1 (February 09, 2021)
--------------------------------------------------------------------------
The 21.1 series debut looks pretty good so far. Thanks again for your
input and comments!
We will be spending a lot of time this year improving and adapting the
code base. As a first glimpse, the changes of this stable update are a
mix of security and reliability updates coupled with preparations for the
update framework revamp we have planned for 21.7. The roadmap is still
not final, but will likely contain long-yearned-for features. Stay tuned.
Here are the full patch notes:
* firewall: change order of shaper delay parameter to prevent parser errors
* firewall: fix multiple PHP warnings regarding category additions
* firewall: fix icon toggle for block and reject (contributed by ElJeffe)
* interfaces: unhide primary IPv6 in overview page
* interfaces: fix IPv6 misalignment in get_interfaces_info()
* reporting: fix sidebar menu collapse for NetFlow link (contributed by Maurice Walker)
* captive portal: validate that static IP address exists when writing the configuration
* firmware: add product status backend for upcoming firmware page redesign
* firmware: opnsense-code will now check out the default release branch
* firmware: opnsense-update adds "-R" option for major release selection
* firmware: opnsense-update will now update repositories if out of sync
* firmware: opnsense-update will attempt to recover from fatal pkg behaviour
* firmware: opnsense-update now correctly redirects stderr on major upgrades
* firmware: opnsense-update now retains vital flag on faulty release type transition
* intrusion detection: clean up rule based additions to prevent collisions with the new policies
* monit: minor bugfixes and UI changes (contributed by Manuel Faux)
* unbound: update documentation URL (contributed by xorbital)
* ui: format packet count with toLocaleString() in interface statistics widget (contributed by bleetsheep)
* ui: add compatibility for JS replaceAll() function
* rc: support reading JSON metadata from plugin version files
* plugins: provide JSON metadata in plugin version files
* plugins: os-dyndns GratisDNS apex domain fix (contributed by Fredrik Rambris)
* plugins: os-nginx upstream TLS verification fix (contributed by kulikov-a)
* plugins: os-theme-cicada 1.26 (contributed by Team Rebellion)
* plugins: os-theme-vicuna 1.2 (contributed by Team Rebellion)
* src: panic when destroying VNET and epair simultaneously `[1] <https://www.freebsd.org/security/advisories/FreeBSD-EN-21:03.vnet.asc>`__
* src: uninitialized file system kernel stack leaks `[2] <https://www.freebsd.org/security/advisories/FreeBSD-SA-21:01.fsdisclosure.asc>`__
* src: Xen guest-triggered out of memory `[3] <https://www.freebsd.org/security/advisories/FreeBSD-SA-21:02.xenoom.asc>`__
* src: update timezone database information `[4] <https://www.freebsd.org/security/advisories/FreeBSD-EN-21:01.tzdata.asc>`__
* ports: dnsmasq 2.84 `[5] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: lighttpd 1.4.59 `[6] <http://www.lighttpd.net/2021/2/2/1.4.59/>`__
* ports: krb5 1.19 `[7] <https://web.mit.edu/kerberos/krb5-1.19/>`__
* ports: monit 5.27.2 `[8] <https://mmonit.com/monit/changes/>`__
* ports: perl 5.32.1 `[9] <https://perldoc.perl.org/5.32.1/perldelta>`__
* ports: sqlite 3.34.1 `[10] <https://sqlite.org/releaselog/3_34_1.html>`__
--------------------------------------------------------------------------
21.1 (January 28, 2021)
--------------------------------------------------------------------------
@ -100,7 +154,7 @@ Here are the full patch notes against 20.7.8:
* interfaces: fix address removal in IPv6 CARP case
* interfaces: pick proper route for 6RD and 6to4 tunnels
* interfaces: support 6RD with single /64 prefix (contributed by Marcel Hofer)
* firewall: support category filters for firewall and NAT rules (sponsored by Modirum)
* firewall: support category filters for firewall and NAT rules `[3] <https://github.com/opnsense/core/issues/4587>`__ (sponsored by Modirum)
* firewall: add live log "host", "port" and "not" filters
* firewall: create an appropriate max-mss scrub rule for IPv6
* firewall: fix anti-spoof option for separate bridge interfaces
@ -122,7 +176,7 @@ Here are the full patch notes against 20.7.8:
* firmware: add ability to run audits from the console
* firmware: show repository in package and plugin overviews
* intrusion detection: replace file-based policy changes with detailed filters
* ipsec: NAT with multiple phase 2 (sponsored by m.a.x. it)
* ipsec: NAT with multiple phase 2 `[4] <https://github.com/opnsense/core/issues/4460>`__ (sponsored by m.a.x. it)
* ipsec: prevent VTI interface to hit spurious 32768 limit
* ipsec: allow mixed IPv4/IPv6 for VTI
* openvpn: added toggle for block-outside-dns (contributed by Julio Camargo)
@ -140,10 +194,10 @@ Here are the full patch notes against 20.7.8:
* ui: add tooltips for service control widget
* ui: move sidebar stage from session to local storage
* ui: upgrade Tokenize2 to v1.3.3
* plugins: os-acme-client 2.3 `[3] <https://github.com/opnsense/plugins/blob/master/security/acme-client/pkg-descr>`__
* plugins: os-bind 1.16 `[4] <https://github.com/opnsense/plugins/blob/master/dns/bind/pkg-descr>`__
* plugins: os-frr 1.21 `[5] <https://github.com/opnsense/plugins/blob/master/net/frr/pkg-descr>`__
* plugins: os-maltrail 1.6 `[6] <https://github.com/opnsense/plugins/blob/master/security/maltrail/pkg-descr>`__ (contributed by jkellerer)
* plugins: os-acme-client 2.3 `[5] <https://github.com/opnsense/plugins/blob/master/security/acme-client/pkg-descr>`__
* plugins: os-bind 1.16 `[6] <https://github.com/opnsense/plugins/blob/master/dns/bind/pkg-descr>`__
* plugins: os-frr 1.21 `[7] <https://github.com/opnsense/plugins/blob/master/net/frr/pkg-descr>`__
* plugins: os-maltrail 1.6 `[8] <https://github.com/opnsense/plugins/blob/master/security/maltrail/pkg-descr>`__ (contributed by jkellerer)
* plugins: os-smart adds cron jobs for useful actions (contributed by Jacek Tomasiak)
* plugins: os-telegraf 1.8.3 adds ping6 ability (contributed by DasSkelett)
* src: fix AES-CCM requests with an AAD size smaller than a single block
@ -153,12 +207,12 @@ Here are the full patch notes against 20.7.8:
* src: netmap tun(4) support adds pseudo addresses to ethernet header emulation (contributed by Sunny Valley Networks)
* src: add a manual page for axp(4) / AMD 10G Ethernet driver
* src: fix traffic graph not showing bandwidth when IPS is enabled
* ports: dnsmasq 2.83 `[7] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: igmpproxy 0.3 `[8] <https://github.com/pali/igmpproxy/releases/tag/0.3>`__
* ports: nss 3.61 `[9] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.61_release_notes>`__
* ports: openldap 2.4.57 `[10] <https://www.openldap.org/software/release/changes.html>`__
* ports: py-netaddr 0.8.0 `[11] <https://pypi.org/project/netaddr/0.8.0/>`__
* ports: sudo 1.9.5p2 `[12] <https://www.sudo.ws/stable.html#1.9.5p2>`__
* ports: dnsmasq 2.83 `[9] <https://www.thekelleys.org.uk/dnsmasq/CHANGELOG>`__
* ports: igmpproxy 0.3 `[10] <https://github.com/pali/igmpproxy/releases/tag/0.3>`__
* ports: nss 3.61 `[11] <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.61_release_notes>`__
* ports: openldap 2.4.57 `[12] <https://www.openldap.org/software/release/changes.html>`__
* ports: py-netaddr 0.8.0 `[13] <https://pypi.org/project/netaddr/0.8.0/>`__
* ports: sudo 1.9.5p2 `[14] <https://www.sudo.ws/stable.html#1.9.5p2>`__
The public key for the 21.1 series is:

Loading…
Cancel
Save