History log of /opensolaris-onvv-gate/usr/src/lib/libsecdb/exec_attr.txt
Revision Date Author Comments
# 13124:8f28cf08bb11 16-Aug-2010 Alexander Kolbasov <Alexander.Kolbasov@Sun.COM>

PSARC 2010/309 Processor Group (PG) Kstats and Tools
6923529 Provide command for printing PG utilization
6764835 Provide command for printing processor group information
6973973 Lonely Cache PG is created on M3000


# 13013:3c7681e3e323 04-Aug-2010 Glenn Lagasse <glenn.lagasse@oracle.com>

PSARC 2010/059 SNAP BE Management
6964804 SNAP BE management into ON
6971379 libbe should capture and give useful error when installgrub or ict.py fails.
6971390 beadm does not support labeled brand zones
6971394 BEADM_ERR_BE_DOES_NOT_EXIST has an extra space
6971397 libbe error messages need internationalization
6971402 Remove be_get_last_zone_be_callback
6971409 be_create_menu returns errors from both be_errno_t and errno sets


# 12918:32a41a5f8110 27-Jul-2010 Jan Friedel <Jan.Friedel@Sun.COM>

PSARC/2009/636 Obsolete getacinfo(3bsm)
PSARC/2009/642 audit_control(4) EOL and removal
PSARC/2010/218 Audit subsystem Rights Profiles
PSARC/2010/220 svc:/system/auditset service
6875456 Solaris Audit configuration in SMF - phase 2 (PSARC/2009/636, PSARC/2009/642)
6942035 audit_binfile(5) leaves unfinished audit logs.
6942041 auditd(1) says "auditd refreshed" on startup.
6943275 audit_remote(5) leaks memory on audit service refresh
6955077 adt_get_mask_from_user() should regard _SC_GETPW_R_SIZE_MAX
6955117 $SRC/lib/libbsm/common/audit_ftpd.c shouldn't hardcode the lenght of usernames (8)
6956169 adt_audit_state() returns non-boolean values


# 12884:8ed2c2ace7da 21-Jul-2010 gww <gary.winiger@oracle.com>

PSARC/2010/253 EOL and interface removal of passmgmt(1M)
6968860 implement PSARC/2010/253 EOL and interface removal of passmgmt(1M)


# 12578:f9062c43c8bc 07-Jun-2010 Glenn Faden <Glenn.Faden@Sun.COM>

4963290 RFE: implement flexible zone administration that doesn't require uid=0
PSARC/2010/132 Delegated Administration for Zones


# 12273:63678502e95e 28-Apr-2010 Casper H.S. Dik <Casper.Dik@Sun.COM>

PSARC 2009/377 In-kernel pfexec implementation.
PSARC 2009/378 Basic File Privileges
PSARC 2010/072 RBAC update: user attrs from profiles
4912090 pfzsh(1) should exist
4912093 pfbash(1) should exist
4912096 pftcsh(1) should exist
6440298 Expand the basic privilege set in order to restrict file access
6859862 Move pfexec into the kernel
6919171 cred_t sidesteps kmem_debug; we need to be able to detect bad hold/free when they occur
6923721 The new SYS_SMB privilege is not backward compatible
6937562 autofs doesn't remove its door when the zone shuts down
6937727 Zones stuck on deathrow; netstack_zone keeps a credential reference to the zone
6940159 Implement PSARC 2010/072


# 12239:7954df8328c0 24-Apr-2010 Paul Cheng <Paul.Cheng@Sun.COM>

6928457 MMS end of feature (fix CDDL, fix packaging)


# 12206:96c3e6ae396d 21-Apr-2010 Paul Cheng <Paul.Cheng@Sun.COM>

PSARC/2010/064 EOF of MMS - Media Management System
6928457 MMS end of feature


# 12019:cfe7a7d0d7f0 26-Mar-2010 Gordon Ross <Gordon.Ross@Sun.COM>

6905120 mount -F smbfs as the Primary Administrator renders the mount point owned by root.
6912466 mount of share from Quantel server fails
6927024 Should defend against opens without closes
6935160 smbfs does not compile with gcc


# 12016:0248e987199b 26-Mar-2010 Girish Moodalbail <Girish.Moodalbail@Sun.COM>

PSARC 2009/306 Brussels II - ipadm and libipadm
PSARC 2010/080 Brussels II addendum
6827318 Brussels Phase II aka ipadm(1m)
6731945 need BSD getifaddrs() API
6909065 explicitly disallow non-contiguous netmasks in the next minor release
6853922 ifconfig dumps core when ether address is non-hexadecimal.
6815806 ipReasmTimeout value should be variable
6567083 nd_getset has some dead and confusing code.
6884466 remove unused tcp/sctp ndd tunables
6928813 Comments at odds with default value of tcp_time_wait_interval
6236982 ifconfig usesrc lets adapter use itself as source address
6936855 modifying the ip6_strict_src_multihoming to non-zero value will unbind V4 IREs


# 11878:ac93462db6d7 09-Mar-2010 Venugopal Iyer <Venu.Iyer@Sun.COM>

PSARC/2009/364 dlstat and flowstat
PSARC/2009/436 Anti-spoofing Link Protection
PSARC/2009/448 pool dladm link property
PSARC/2009/501 Dynamic Ring Grouping on NICs
PSARC/2009/638 Public GLDv3 Interfaces
PSARC/2010/074 Crossbow resource usage updates
6838175 mac_tx should be able to send out a packet without a configured address
6806552 single MAC default TX ring doesn't scale
6809686 back-to-back LACP not recovering after removing one of the aggregated ports
6902209 setting maxbw to zero requires an intermediate reset-linkprop to take effect
6855972 Bind interrupts to the same CPU as poll thread using new interrupt APIs
6863945 aggr pseudo Tx rings
6796839 allow CPU pools to be associated with data-links
6526471 data-links assigned to an exclusive zone should seamlessly be bound the zone's CPUs
6802595 Per links stats can use some improvement
6889685 Crossbow should provide control over provision of h/w rings to MAC clients.
6708310 ixgbe needs to support VMDq
6869019 ixgbe should support IRM (Interrupt Resource Management framework)
6902266 vnet should support entry point for per ring stat querying
6926790 Integrate Link Protection Phase II
6930358 Make the core set of GLDv3 driver APIs committed
6901419 dladm create-aggr -u incorrectly rejects some valid ethernet addresses
6717042 should support "cpus" link properties for aggregations
6908184 bge_set_priv_prop() and bge_get_priv_prop() can't agree on the set of private properties
6907617 bge_m_getprop() shouldn't return default values for read-only properties
6900833 unused code in vnic_impl.h can be removed


# 11876:5fce03ad05c6 09-Mar-2010 Jim Dunham <James.Dunham@Sun.COM>

PSARC/2010/006 EOF of iSCSI Target Daemon
6914623 Remove iSCSI Target Daemon from ON Consolidation


# 11838:32bb5d254240 02-Mar-2010 Liane Praza <Liane.Praza@Sun.COM>

PSARC 2010/067 Interim modernization updates
6915312 ON should be able to build IPS packages natively
6281004 docbook.dtd is obsolete and unused
6490919 strange file in onnv-gate
6878498 update tools proto ${ROOT} to include ${MACH} and make nightly.sh copy it into parent repository
6888427 SVM packages should drop legacy objects
6893530 Some header files can be opened up
6903324 sharemgr should either use isaexec or not build 64-bit commands
6920651 mktpl will inadvertently reuse stale license files for empty license lists
6920674 svvs kmods should not be built during an open build
Portions contributed by Rich Lowe <richlowe@richlowe.net>


# 11767:8f30d0e611c6 25-Feb-2010 Anurag S. Maskey <Anurag.Maskey@Sun.COM>

PSARC/2008/532 NWAM Phase 1
PSARC/2009/577 Network Auto-Magic (NWAM) Phase 1 Updates
PSARC/2010/049 Network Auto-Magic (NWAM) Phase 1 Updates part 2
4087814 User friendly utility wanted for network config, able to add network interfaces.
6509720 support configuration using DHCP "inform" and static IP address
6553627 network/physical:default and network/physical:nwam should be mutually-exclusive (perhaps a property)
6609581 nwam does not start the dns/client service after configuring the network
6664072 nwam profiles should include name service configuration properties
6723947 setting static MAC address should be possible
6794043 NWAM needs more complete profile support
6914190 Support for unmanaged network interfaces in NWAM - hands off
6921971 nwamd fails to run teardown/net-svc after suspend/resume


# 11262:b7ebfbf2359e 06-Dec-2009 Raja Andra <Rajagopal.Andra@Sun.COM>

6874309 Remove NIS+ from Solaris


# 11064:51207b1af901 13-Nov-2009 Casper H.S. Dik <Casper.Dik@Sun.COM>

6234679 useradd, usermod, userdel fails when run by a user that has the "User Management" profile assigned.


# 10652:9d0aff74d6fd 25-Sep-2009 Hyon Kim <Hyon.Kim@Sun.COM>

PSARC/2008/687 T11 Storage Management HBA API(SM-HBA)
6795795 Provide management utility for SAS Gen-2(SAS-2 compliant) HBAs.
6795797 Provide SM-HBA wrapper library for SAS Gen-2(SAS-2 compliant) HBAs.
6795800 Provide SM-HBA Vendor Specific Library for Sun SAS-2 HBAs.


# 9552:8d9ff54ba154 06-May-2009 Ritwik Ghoshal <Ritwik.Ghoshal@Sun.COM>

6464916 "/etc/security/exec_attr" contains incorrect policy and typos


# 9537:587ddeb721a7 04-May-2009 Erwin T Tsaur <Erwin.Tsaur@Sun.COM>

6788312 Array overrun in pci_tools
6799018 pcitool should be available as a supported tool on Solaris 10
PSARC 2009/215 PCITool Public Interrupts


# 9298:5ecf9483b3ec 07-Apr-2009 William Young <William.Young@Sun.COM>

6436517 bart needs to be large files aware to support ZFS roots greater than 2TB
6753297 Running bart on zfs root file system in s10u6_07 will core dump
6239261 RFE: Add File Integrity rights profile for BART


# 8275:7c223a798022 04-Dec-2008 Eric Cheng

PSARC/2006/357 Crossbow - Network Virtualization and Resource Management
6498311 Crossbow - Network Virtualization and Resource Management
6402493 DLPI provider loopback behavior should be improved
6453165 move mac capabs definitions outside mac.h
6338667 Need ability to use NAT for non-global zones
6692884 several threads hung due to deadlock scenario between aggr and mac
6768302 dls: soft_ring_bind/unbind race can panic in thread_affinity_set with cpu_id == -1
6635849 race between lacp_xmit_sm() and aggr_m_stop() ends in panic
6742712 potential message double free in the aggr driver
6754299 a potential race between aggr_m_tx() and aggr_port_delete()
6485324 mi_data_lock recursively held when enabling promiscuous mode on an aggregation
6442559 Forwarding perf bottleneck due to mac_rx() calls
6505462 assertion failure after removing a port from a snooped aggregation
6716664 need to add src/dst IP address to soft ring fanout


# 8023:faf256d5c16c 06-Nov-2008 Philip Kirk <Phil.Kirk@Sun.COM>

PSARC/2006/475 Clearview: IP Observability Devices
4085089 add a feature to enable 'snooping' of the loopback traffic
6753688 ip netinfo has no need for separate create and dispatch functions
6755448 ifconfig wedged in SIOCLIFREMOVEIF
6756483 incorrect ASSERT() in ip_delmulti[_v6]()
5092073 RFE: allow snoop to filter on zonename or zoneid
6606991 panic assertion failure !ill->ill_join_allmulti for multicast router
6760922 devname doesn't handle stale dev_t's in sdev_node cache entries


# 7836:4e95154b5b7a 14-Oct-2008 John Forte <John.Forte@Sun.COM>

6745433 Merge NWS consolidation into OS/Net consolidation


# 7734:c46e039795b8 29-Sep-2008 David Powell <David.Powell@sun.com>

6751138 libc's lint library is missing definition for __assert_c99
6751161 PSARC 2008/551 coreadm configuration refinements


# 7577:4eedc1cf145c 12-Sep-2008 Brian Kuyper <Brian.Kuyper@Sun.COM>

6744920 Move the rbac profiles in MMS to the ON standard location


# 7408:eff7960d93cd 26-Aug-2008 Sebastien Roy <Sebastien.Roy@Sun.COM>

PSARC 2008/473 Fine-Grained Privileges for Datalink Administration
6695904 least privileges for datalink actions
6729477 pcwl accidentally requires privileges for WLAN_GET_PARAM ioctl
6679049 ucred_t leak in dlmgmtd
6738245 dld's _init() doesn't teardown if mod_install() fails
6738987 i.devpolicy pattern matching accidentally matches random lines


# 7103:3cde99325878 15-Jul-2008 ml93401

PSARC 2008/087 Extended Accounting Conversion to SMF
4520887 acctadm settings should be persistent by default across reboots
4674288 acctadm misreports flow accounting resource type errors
5082833 RFE: exacct and acctadm should be converted to smf(5)
6400978 acctadm -u not run during boot
6481931 acctadm -u fails in a non-global zone
6694576 race in ac_file_set() can lead to corrupted accounting file


# 6278:bacc304c08f2 25-Mar-2008 jdunham

6591294 exec attributes entry for iscsitadm incorrect
6638031 ACLs created against ZVOLs via shareiscsi=on are not persistent
6652170 iSCSI Target leaks memory in the current SCF implementation


# 6007:d57e38e8fdd1 13-Feb-2008 thurlow

PSARC 2005/695 CIFS Client on Solaris
PSARC 2007/303 pam_smb_login
PSARC 2008/073 CIFS Client on Solaris - Updates
6651904 CIFS Client - PSARC 2005/695


# 5086:b89a91e959b2 18-Sep-2007 semery

PSARC 2007/335 kdcmgr utility
6231080 Solaris Kerberos needs a cmdline utility to auto-configure a master/slave KDC
6588844 gkadmin's help file uses user-visible SCCS keywords
6596185 kadmin negates -allow_tix when adding a principal record
6598545 Client key decrypt receives bad integrity check when master key is AES*


# 4960:a4746a82a247 29-Aug-2007 willf

PSARC/2006/277 Support for Kerberos Records in LDAP Directory
6399903 Support for Kerberos Records in LDAP Directory
6520554 MIT bug #5427 with krb5_kt_get_name()
6597851 dmake lint in usr/src/lib/gss_mechs/mech_krb5 broken


# 4746:0bc0c48f4304 27-Jul-2007 rica

PSARC 2007/254 - Enabling method for Trusted Extensions
6432114 [tjds] cannot login via gdm unless clearance is set to admin_high
6533113 split install and enabling of Trusted Extensions
6533118 move TX source from TLC to ON gate
6542578 TLC putback requires i.pamconf change similar to the kerberos solution.
6552207 txzonemgr does not configure loopback mounts for /etc/passwd and /etc/shadow when creating zones
6552253 solaris.smf.manage.labels should allow for permanent as well as temporary enable/disable of labeld
6555057 txzonemgr assumes LANG is valid
6557684 pam_tsol_account could use a thorough house cleaning
6561392 txzonemgr should work from Zone Management profile
6565347 txzonemgr failed to add an interface to a zone


# 4581:b6104e41b06c 02-Jul-2007 sherrym

PSARC/2007/349 Intel Microcode Update Support
6558456 Need to support microcode update on Intel platforms


# 4465:9a4c9f167839 13-Jun-2007 pwernau

6560798 Network IPsec Management profile should be refined
6561805 Addition of Network IPsec Management profile does not purge old entries from Network Security


# 4235:037e335b7d68 14-May-2007 markfen

PSARC 2007/200 - Dedicated SMF services for IPsec/IKE
6185380 IPsec should be a separate (set) of smf(5) services
6440610 missing preshared remoteid line causes in.iked core dump on reading config
6462741 ipsecconf should have an option to check config file syntax
6467954 ipseckey exit code on failure inconsistent
6468456 ipsecconf uses strcpy()
6479903 in.iked with SMF should use _enter_daemon_lock()
6488927 ipseckey(1M) could do a better job of dealing with multiple errors
6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec
6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile
6529086 ipsec utilities can't deal with large files
6538478 Timestamp in in.iked debug output does not understand daylight savings time
6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.
6543263 ikeadm uses strcpy()
6543267 ipseckey uses strcpy()
6544087 memory leak with preshared key reloading


# 3999:666384b31577 09-Apr-2007 jacobs

6222297 lpsched and lpshut should be corrected/removed from exec_attr
6454630 print subsystem enable and disable commands not RBAC capable
6538881 lpadmin cannot create queue even with Print Management profile
6539897 uri interface script should handle common device-uri forms


# 3781:41d7a70cdf1d 08-Mar-2007 ceastha

PSARC 2006/647 PPD Manager
5100134 print/rfc1179 ends up by default in "offline" state
6236968 No documented way to add PPD file to ppdcache
6527759 Need to delete legacy print/cleanup service
6529794 lpsched not started after first local printer is added


# 3501:c8757971fd8e 26-Jan-2007 wyllys

6507361 pktool help doesn't
6514823 kmfcfg is misspelled in exec_attr
6515109 Error message when using "pktool gencert" should use 'serial' instead of 'serno'


# 3457:95f0a08d05e5 21-Jan-2007 jc156560

PSARC 2005/204 RaidCfg project
PSARC 2006/663 RaidCfg mpt adjustment
6508590 raidctl utility should use the pass_thru interface for mpt support


# 3448:aaf16568054b 19-Jan-2007 dh155122

PSARC 2006/366 IP Instances
6289221 RFE: Need virtualized ip-stack for each local zone
6512601 panic in ipsec_in_tag - allocation failure
6514637 error message from dhcpagent: add_pkt_opt: option type 60 is missing required value
6364643 RFE: allow persistent setting of interface flags per zone
6307539 RFE: Invalid network address causes zone boot failure
5041214 Allow IPMP configuration with zones
5005887 RFE: zoneadmd should support plumbing an interface via DHCP
4991139 RFE: zones should provide a mechanism to configure a defaultrouter for a zone
6218378 zoneadmd doesn't set the netmask for non-loopback addresses hosted on lo0
4963280 zones: need to virtualize the IPv6 default address selection mechanism
4963285 zones: need support of stateless address autoconfiguration for IPv6
5048068 zones don't boot if one of its interfaces has failed
5057154 RFE: ability to change interface status from within a zone
4963287 zones should support the plumbing of the first (and only) logical interface
4978517 TCP privileged port space should be partitioned per zone
5023347 zones don't work well with network routes other than default
4963372 investigate whether global zone can act as a router for local zones
6378364 RFE: Allow each zone to have its own virtual IPFilter


# 3389:d6439d9c59e0 08-Jan-2007 ericheng

6498943 auditing doesn't work if dladm is run as a non-root user
6503946 live upgrade does not handle relocation of aggregation.conf file


# 3147:2789cc0027be 20-Nov-2006 xc151355

PSARC/2006/406 WiFi for GLDv3
PSARC/2006/517 WiFi for GLDv3 Addendum
PSARC/2006/623 WiFi for GLDv3 Addendum #2
6253476 dladm exec_attr entry doesn't allow show-link to work
6362391 ath driver needs to be updated to use the latest HAL
6364198 system crashes if multiple ath driver instances are modunload'ed
6367259 ath driver needs to support GLDv3
6407181 ath driver panics in ath_rate_update function
6421983 ath driver needs shared_key authmode support
6472427 ath driver causes watchdog timeout error
6484943 integrate WiFi/GLDv3


# 3100:50bae443cce5 12-Nov-2006 tz204579

6370612 audit(1M) doesn't work with RBAC due to getuid(2) check


# 3089:8ddeb2ace8aa 10-Nov-2006 wyllys

PSARC 2005/074 Solaris Key Management Framework
6224192 Solaris needs unified key management interfaces


# 3034:3199b356d00f 01-Nov-2006 dougm

PSARC 2005/374 Share management improvements
6281048 NFS needs simplified administration


# 2958:98aa41c076f5 20-Oct-2006 dr146992

PSARC/2005/334 Packet Filtering Hooks
PSARC/2006/321 ARP packet filtering Hooks
6401219 use of pullupmsg() considered destructive - clears h/w checksum flags
6418698 PSARC/2005/334 - Packet Filtering Hooks API
6449290 package prototype files in usr/src/pkgdefs/SUNWipfr missing CDDL
6449292 package prototype files in usr/src/pkgdefs/SUNWipfu missing CDDL
6449296 Makefiles for ipf kernel module building missing CDDL
6473996 "fastroute" + "nat" packets cause memory leaks in ipfilter


# 2314:4fe9bb63bd02 30-Jun-2006 mcneal

PSARC 2005/441 iSCSI Target
6392513 Need iSCSI Target for Solaris


# 2115:a40e8f141552 02-Jun-2006 vikram

6351677 bootadm should allow certain sub-commands to be run by non-root users
6369346 bootadm emits error message when running init under pfexec
6429888 bootadm doesn't check arguments as well as it could


# 1583:f5bab1129c55 09-Mar-2006 talley

6395964 availdevs should be included in ZFS execution profile


# 996:2f87885a658c 25-Nov-2005 eschrock

6343625 ZFS RBAC integration is incomplete


# 898:64b2a371a6bd 12-Nov-2005 kais

PSARC/2005/625 Greyhound - Solaris Kernel SSL proxy
4931229 Kernel-level SSL proxy


# 862:12c6677a0383 07-Nov-2005 vikram

6315667 bootadm complains when running init under pfexec


# 789:b348f31ed315 31-Oct-2005 ahrens

PSARC 2002/240 ZFS
6338653 Integrate ZFS
PSARC 2004/652 - DKIOCFLUSH
5096886 Write caching disks need mechanism to flush cache to physical media


# 0:68f95e015346 14-Jun-2005 stevel@tonic-gate

OpenSolaris Launch


# 13124:8f28cf08bb11 16-Aug-2010 Alexander Kolbasov <Alexander.Kolbasov@Sun.COM>

PSARC 2010/309 Processor Group (PG) Kstats and Tools
6923529 Provide command for printing PG utilization
6764835 Provide command for printing processor group information
6973973 Lonely Cache PG is created on M3000


# 13013:3c7681e3e323 04-Aug-2010 Glenn Lagasse <glenn.lagasse@oracle.com>

PSARC 2010/059 SNAP BE Management
6964804 SNAP BE management into ON
6971379 libbe should capture and give useful error when installgrub or ict.py fails.
6971390 beadm does not support labeled brand zones
6971394 BEADM_ERR_BE_DOES_NOT_EXIST has an extra space
6971397 libbe error messages need internationalization
6971402 Remove be_get_last_zone_be_callback
6971409 be_create_menu returns errors from both be_errno_t and errno sets


# 12918:32a41a5f8110 27-Jul-2010 Jan Friedel <Jan.Friedel@Sun.COM>

PSARC/2009/636 Obsolete getacinfo(3bsm)
PSARC/2009/642 audit_control(4) EOL and removal
PSARC/2010/218 Audit subsystem Rights Profiles
PSARC/2010/220 svc:/system/auditset service
6875456 Solaris Audit configuration in SMF - phase 2 (PSARC/2009/636, PSARC/2009/642)
6942035 audit_binfile(5) leaves unfinished audit logs.
6942041 auditd(1) says "auditd refreshed" on startup.
6943275 audit_remote(5) leaks memory on audit service refresh
6955077 adt_get_mask_from_user() should regard _SC_GETPW_R_SIZE_MAX
6955117 $SRC/lib/libbsm/common/audit_ftpd.c shouldn't hardcode the lenght of usernames (8)
6956169 adt_audit_state() returns non-boolean values


# 12884:8ed2c2ace7da 21-Jul-2010 gww <gary.winiger@oracle.com>

PSARC/2010/253 EOL and interface removal of passmgmt(1M)
6968860 implement PSARC/2010/253 EOL and interface removal of passmgmt(1M)


# 12578:f9062c43c8bc 07-Jun-2010 Glenn Faden <Glenn.Faden@Sun.COM>

4963290 RFE: implement flexible zone administration that doesn't require uid=0
PSARC/2010/132 Delegated Administration for Zones


# 12273:63678502e95e 28-Apr-2010 Casper H.S. Dik <Casper.Dik@Sun.COM>

PSARC 2009/377 In-kernel pfexec implementation.
PSARC 2009/378 Basic File Privileges
PSARC 2010/072 RBAC update: user attrs from profiles
4912090 pfzsh(1) should exist
4912093 pfbash(1) should exist
4912096 pftcsh(1) should exist
6440298 Expand the basic privilege set in order to restrict file access
6859862 Move pfexec into the kernel
6919171 cred_t sidesteps kmem_debug; we need to be able to detect bad hold/free when they occur
6923721 The new SYS_SMB privilege is not backward compatible
6937562 autofs doesn't remove its door when the zone shuts down
6937727 Zones stuck on deathrow; netstack_zone keeps a credential reference to the zone
6940159 Implement PSARC 2010/072


# 12239:7954df8328c0 24-Apr-2010 Paul Cheng <Paul.Cheng@Sun.COM>

6928457 MMS end of feature (fix CDDL, fix packaging)


# 12206:96c3e6ae396d 21-Apr-2010 Paul Cheng <Paul.Cheng@Sun.COM>

PSARC/2010/064 EOF of MMS - Media Management System
6928457 MMS end of feature


# 12019:cfe7a7d0d7f0 26-Mar-2010 Gordon Ross <Gordon.Ross@Sun.COM>

6905120 mount -F smbfs as the Primary Administrator renders the mount point owned by root.
6912466 mount of share from Quantel server fails
6927024 Should defend against opens without closes
6935160 smbfs does not compile with gcc


# 12016:0248e987199b 26-Mar-2010 Girish Moodalbail <Girish.Moodalbail@Sun.COM>

PSARC 2009/306 Brussels II - ipadm and libipadm
PSARC 2010/080 Brussels II addendum
6827318 Brussels Phase II aka ipadm(1m)
6731945 need BSD getifaddrs() API
6909065 explicitly disallow non-contiguous netmasks in the next minor release
6853922 ifconfig dumps core when ether address is non-hexadecimal.
6815806 ipReasmTimeout value should be variable
6567083 nd_getset has some dead and confusing code.
6884466 remove unused tcp/sctp ndd tunables
6928813 Comments at odds with default value of tcp_time_wait_interval
6236982 ifconfig usesrc lets adapter use itself as source address
6936855 modifying the ip6_strict_src_multihoming to non-zero value will unbind V4 IREs


# 11878:ac93462db6d7 09-Mar-2010 Venugopal Iyer <Venu.Iyer@Sun.COM>

PSARC/2009/364 dlstat and flowstat
PSARC/2009/436 Anti-spoofing Link Protection
PSARC/2009/448 pool dladm link property
PSARC/2009/501 Dynamic Ring Grouping on NICs
PSARC/2009/638 Public GLDv3 Interfaces
PSARC/2010/074 Crossbow resource usage updates
6838175 mac_tx should be able to send out a packet without a configured address
6806552 single MAC default TX ring doesn't scale
6809686 back-to-back LACP not recovering after removing one of the aggregated ports
6902209 setting maxbw to zero requires an intermediate reset-linkprop to take effect
6855972 Bind interrupts to the same CPU as poll thread using new interrupt APIs
6863945 aggr pseudo Tx rings
6796839 allow CPU pools to be associated with data-links
6526471 data-links assigned to an exclusive zone should seamlessly be bound the zone's CPUs
6802595 Per links stats can use some improvement
6889685 Crossbow should provide control over provision of h/w rings to MAC clients.
6708310 ixgbe needs to support VMDq
6869019 ixgbe should support IRM (Interrupt Resource Management framework)
6902266 vnet should support entry point for per ring stat querying
6926790 Integrate Link Protection Phase II
6930358 Make the core set of GLDv3 driver APIs committed
6901419 dladm create-aggr -u incorrectly rejects some valid ethernet addresses
6717042 should support "cpus" link properties for aggregations
6908184 bge_set_priv_prop() and bge_get_priv_prop() can't agree on the set of private properties
6907617 bge_m_getprop() shouldn't return default values for read-only properties
6900833 unused code in vnic_impl.h can be removed


# 11876:5fce03ad05c6 09-Mar-2010 Jim Dunham <James.Dunham@Sun.COM>

PSARC/2010/006 EOF of iSCSI Target Daemon
6914623 Remove iSCSI Target Daemon from ON Consolidation


# 11838:32bb5d254240 02-Mar-2010 Liane Praza <Liane.Praza@Sun.COM>

PSARC 2010/067 Interim modernization updates
6915312 ON should be able to build IPS packages natively
6281004 docbook.dtd is obsolete and unused
6490919 strange file in onnv-gate
6878498 update tools proto ${ROOT} to include ${MACH} and make nightly.sh copy it into parent repository
6888427 SVM packages should drop legacy objects
6893530 Some header files can be opened up
6903324 sharemgr should either use isaexec or not build 64-bit commands
6920651 mktpl will inadvertently reuse stale license files for empty license lists
6920674 svvs kmods should not be built during an open build
Portions contributed by Rich Lowe <richlowe@richlowe.net>


# 11767:8f30d0e611c6 25-Feb-2010 Anurag S. Maskey <Anurag.Maskey@Sun.COM>

PSARC/2008/532 NWAM Phase 1
PSARC/2009/577 Network Auto-Magic (NWAM) Phase 1 Updates
PSARC/2010/049 Network Auto-Magic (NWAM) Phase 1 Updates part 2
4087814 User friendly utility wanted for network config, able to add network interfaces.
6509720 support configuration using DHCP "inform" and static IP address
6553627 network/physical:default and network/physical:nwam should be mutually-exclusive (perhaps a property)
6609581 nwam does not start the dns/client service after configuring the network
6664072 nwam profiles should include name service configuration properties
6723947 setting static MAC address should be possible
6794043 NWAM needs more complete profile support
6914190 Support for unmanaged network interfaces in NWAM - hands off
6921971 nwamd fails to run teardown/net-svc after suspend/resume


# 11262:b7ebfbf2359e 06-Dec-2009 Raja Andra <Rajagopal.Andra@Sun.COM>

6874309 Remove NIS+ from Solaris


# 11064:51207b1af901 13-Nov-2009 Casper H.S. Dik <Casper.Dik@Sun.COM>

6234679 useradd, usermod, userdel fails when run by a user that has the "User Management" profile assigned.


# 10652:9d0aff74d6fd 25-Sep-2009 Hyon Kim <Hyon.Kim@Sun.COM>

PSARC/2008/687 T11 Storage Management HBA API(SM-HBA)
6795795 Provide management utility for SAS Gen-2(SAS-2 compliant) HBAs.
6795797 Provide SM-HBA wrapper library for SAS Gen-2(SAS-2 compliant) HBAs.
6795800 Provide SM-HBA Vendor Specific Library for Sun SAS-2 HBAs.


# 9552:8d9ff54ba154 06-May-2009 Ritwik Ghoshal <Ritwik.Ghoshal@Sun.COM>

6464916 "/etc/security/exec_attr" contains incorrect policy and typos


# 9537:587ddeb721a7 04-May-2009 Erwin T Tsaur <Erwin.Tsaur@Sun.COM>

6788312 Array overrun in pci_tools
6799018 pcitool should be available as a supported tool on Solaris 10
PSARC 2009/215 PCITool Public Interrupts


# 9298:5ecf9483b3ec 07-Apr-2009 William Young <William.Young@Sun.COM>

6436517 bart needs to be large files aware to support ZFS roots greater than 2TB
6753297 Running bart on zfs root file system in s10u6_07 will core dump
6239261 RFE: Add File Integrity rights profile for BART


# 8275:7c223a798022 04-Dec-2008 Eric Cheng

PSARC/2006/357 Crossbow - Network Virtualization and Resource Management
6498311 Crossbow - Network Virtualization and Resource Management
6402493 DLPI provider loopback behavior should be improved
6453165 move mac capabs definitions outside mac.h
6338667 Need ability to use NAT for non-global zones
6692884 several threads hung due to deadlock scenario between aggr and mac
6768302 dls: soft_ring_bind/unbind race can panic in thread_affinity_set with cpu_id == -1
6635849 race between lacp_xmit_sm() and aggr_m_stop() ends in panic
6742712 potential message double free in the aggr driver
6754299 a potential race between aggr_m_tx() and aggr_port_delete()
6485324 mi_data_lock recursively held when enabling promiscuous mode on an aggregation
6442559 Forwarding perf bottleneck due to mac_rx() calls
6505462 assertion failure after removing a port from a snooped aggregation
6716664 need to add src/dst IP address to soft ring fanout


# 8023:faf256d5c16c 06-Nov-2008 Philip Kirk <Phil.Kirk@Sun.COM>

PSARC/2006/475 Clearview: IP Observability Devices
4085089 add a feature to enable 'snooping' of the loopback traffic
6753688 ip netinfo has no need for separate create and dispatch functions
6755448 ifconfig wedged in SIOCLIFREMOVEIF
6756483 incorrect ASSERT() in ip_delmulti[_v6]()
5092073 RFE: allow snoop to filter on zonename or zoneid
6606991 panic assertion failure !ill->ill_join_allmulti for multicast router
6760922 devname doesn't handle stale dev_t's in sdev_node cache entries


# 7836:4e95154b5b7a 14-Oct-2008 John Forte <John.Forte@Sun.COM>

6745433 Merge NWS consolidation into OS/Net consolidation


# 7734:c46e039795b8 29-Sep-2008 David Powell <David.Powell@sun.com>

6751138 libc's lint library is missing definition for __assert_c99
6751161 PSARC 2008/551 coreadm configuration refinements


# 7577:4eedc1cf145c 12-Sep-2008 Brian Kuyper <Brian.Kuyper@Sun.COM>

6744920 Move the rbac profiles in MMS to the ON standard location


# 7408:eff7960d93cd 26-Aug-2008 Sebastien Roy <Sebastien.Roy@Sun.COM>

PSARC 2008/473 Fine-Grained Privileges for Datalink Administration
6695904 least privileges for datalink actions
6729477 pcwl accidentally requires privileges for WLAN_GET_PARAM ioctl
6679049 ucred_t leak in dlmgmtd
6738245 dld's _init() doesn't teardown if mod_install() fails
6738987 i.devpolicy pattern matching accidentally matches random lines


# 7103:3cde99325878 15-Jul-2008 ml93401

PSARC 2008/087 Extended Accounting Conversion to SMF
4520887 acctadm settings should be persistent by default across reboots
4674288 acctadm misreports flow accounting resource type errors
5082833 RFE: exacct and acctadm should be converted to smf(5)
6400978 acctadm -u not run during boot
6481931 acctadm -u fails in a non-global zone
6694576 race in ac_file_set() can lead to corrupted accounting file


# 6278:bacc304c08f2 25-Mar-2008 jdunham

6591294 exec attributes entry for iscsitadm incorrect
6638031 ACLs created against ZVOLs via shareiscsi=on are not persistent
6652170 iSCSI Target leaks memory in the current SCF implementation


# 6007:d57e38e8fdd1 13-Feb-2008 thurlow

PSARC 2005/695 CIFS Client on Solaris
PSARC 2007/303 pam_smb_login
PSARC 2008/073 CIFS Client on Solaris - Updates
6651904 CIFS Client - PSARC 2005/695


# 5086:b89a91e959b2 18-Sep-2007 semery

PSARC 2007/335 kdcmgr utility
6231080 Solaris Kerberos needs a cmdline utility to auto-configure a master/slave KDC
6588844 gkadmin's help file uses user-visible SCCS keywords
6596185 kadmin negates -allow_tix when adding a principal record
6598545 Client key decrypt receives bad integrity check when master key is AES*


# 4960:a4746a82a247 29-Aug-2007 willf

PSARC/2006/277 Support for Kerberos Records in LDAP Directory
6399903 Support for Kerberos Records in LDAP Directory
6520554 MIT bug #5427 with krb5_kt_get_name()
6597851 dmake lint in usr/src/lib/gss_mechs/mech_krb5 broken


# 4746:0bc0c48f4304 27-Jul-2007 rica

PSARC 2007/254 - Enabling method for Trusted Extensions
6432114 [tjds] cannot login via gdm unless clearance is set to admin_high
6533113 split install and enabling of Trusted Extensions
6533118 move TX source from TLC to ON gate
6542578 TLC putback requires i.pamconf change similar to the kerberos solution.
6552207 txzonemgr does not configure loopback mounts for /etc/passwd and /etc/shadow when creating zones
6552253 solaris.smf.manage.labels should allow for permanent as well as temporary enable/disable of labeld
6555057 txzonemgr assumes LANG is valid
6557684 pam_tsol_account could use a thorough house cleaning
6561392 txzonemgr should work from Zone Management profile
6565347 txzonemgr failed to add an interface to a zone


# 4581:b6104e41b06c 02-Jul-2007 sherrym

PSARC/2007/349 Intel Microcode Update Support
6558456 Need to support microcode update on Intel platforms


# 4465:9a4c9f167839 13-Jun-2007 pwernau

6560798 Network IPsec Management profile should be refined
6561805 Addition of Network IPsec Management profile does not purge old entries from Network Security


# 4235:037e335b7d68 14-May-2007 markfen

PSARC 2007/200 - Dedicated SMF services for IPsec/IKE
6185380 IPsec should be a separate (set) of smf(5) services
6440610 missing preshared remoteid line causes in.iked core dump on reading config
6462741 ipsecconf should have an option to check config file syntax
6467954 ipseckey exit code on failure inconsistent
6468456 ipsecconf uses strcpy()
6479903 in.iked with SMF should use _enter_daemon_lock()
6488927 ipseckey(1M) could do a better job of dealing with multiple errors
6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec
6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile
6529086 ipsec utilities can't deal with large files
6538478 Timestamp in in.iked debug output does not understand daylight savings time
6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.
6543263 ikeadm uses strcpy()
6543267 ipseckey uses strcpy()
6544087 memory leak with preshared key reloading


# 3999:666384b31577 09-Apr-2007 jacobs

6222297 lpsched and lpshut should be corrected/removed from exec_attr
6454630 print subsystem enable and disable commands not RBAC capable
6538881 lpadmin cannot create queue even with Print Management profile
6539897 uri interface script should handle common device-uri forms


# 3781:41d7a70cdf1d 08-Mar-2007 ceastha

PSARC 2006/647 PPD Manager
5100134 print/rfc1179 ends up by default in "offline" state
6236968 No documented way to add PPD file to ppdcache
6527759 Need to delete legacy print/cleanup service
6529794 lpsched not started after first local printer is added


# 3501:c8757971fd8e 26-Jan-2007 wyllys

6507361 pktool help doesn't
6514823 kmfcfg is misspelled in exec_attr
6515109 Error message when using "pktool gencert" should use 'serial' instead of 'serno'


# 3457:95f0a08d05e5 21-Jan-2007 jc156560

PSARC 2005/204 RaidCfg project
PSARC 2006/663 RaidCfg mpt adjustment
6508590 raidctl utility should use the pass_thru interface for mpt support


# 3448:aaf16568054b 19-Jan-2007 dh155122

PSARC 2006/366 IP Instances
6289221 RFE: Need virtualized ip-stack for each local zone
6512601 panic in ipsec_in_tag - allocation failure
6514637 error message from dhcpagent: add_pkt_opt: option type 60 is missing required value
6364643 RFE: allow persistent setting of interface flags per zone
6307539 RFE: Invalid network address causes zone boot failure
5041214 Allow IPMP configuration with zones
5005887 RFE: zoneadmd should support plumbing an interface via DHCP
4991139 RFE: zones should provide a mechanism to configure a defaultrouter for a zone
6218378 zoneadmd doesn't set the netmask for non-loopback addresses hosted on lo0
4963280 zones: need to virtualize the IPv6 default address selection mechanism
4963285 zones: need support of stateless address autoconfiguration for IPv6
5048068 zones don't boot if one of its interfaces has failed
5057154 RFE: ability to change interface status from within a zone
4963287 zones should support the plumbing of the first (and only) logical interface
4978517 TCP privileged port space should be partitioned per zone
5023347 zones don't work well with network routes other than default
4963372 investigate whether global zone can act as a router for local zones
6378364 RFE: Allow each zone to have its own virtual IPFilter


# 3389:d6439d9c59e0 08-Jan-2007 ericheng

6498943 auditing doesn't work if dladm is run as a non-root user
6503946 live upgrade does not handle relocation of aggregation.conf file


# 3147:2789cc0027be 20-Nov-2006 xc151355

PSARC/2006/406 WiFi for GLDv3
PSARC/2006/517 WiFi for GLDv3 Addendum
PSARC/2006/623 WiFi for GLDv3 Addendum #2
6253476 dladm exec_attr entry doesn't allow show-link to work
6362391 ath driver needs to be updated to use the latest HAL
6364198 system crashes if multiple ath driver instances are modunload'ed
6367259 ath driver needs to support GLDv3
6407181 ath driver panics in ath_rate_update function
6421983 ath driver needs shared_key authmode support
6472427 ath driver causes watchdog timeout error
6484943 integrate WiFi/GLDv3


# 3100:50bae443cce5 12-Nov-2006 tz204579

6370612 audit(1M) doesn't work with RBAC due to getuid(2) check


# 3089:8ddeb2ace8aa 10-Nov-2006 wyllys

PSARC 2005/074 Solaris Key Management Framework
6224192 Solaris needs unified key management interfaces


# 3034:3199b356d00f 01-Nov-2006 dougm

PSARC 2005/374 Share management improvements
6281048 NFS needs simplified administration


# 2958:98aa41c076f5 20-Oct-2006 dr146992

PSARC/2005/334 Packet Filtering Hooks
PSARC/2006/321 ARP packet filtering Hooks
6401219 use of pullupmsg() considered destructive - clears h/w checksum flags
6418698 PSARC/2005/334 - Packet Filtering Hooks API
6449290 package prototype files in usr/src/pkgdefs/SUNWipfr missing CDDL
6449292 package prototype files in usr/src/pkgdefs/SUNWipfu missing CDDL
6449296 Makefiles for ipf kernel module building missing CDDL
6473996 "fastroute" + "nat" packets cause memory leaks in ipfilter


# 2314:4fe9bb63bd02 30-Jun-2006 mcneal

PSARC 2005/441 iSCSI Target
6392513 Need iSCSI Target for Solaris


# 2115:a40e8f141552 02-Jun-2006 vikram

6351677 bootadm should allow certain sub-commands to be run by non-root users
6369346 bootadm emits error message when running init under pfexec
6429888 bootadm doesn't check arguments as well as it could


# 1583:f5bab1129c55 09-Mar-2006 talley

6395964 availdevs should be included in ZFS execution profile


# 996:2f87885a658c 25-Nov-2005 eschrock

6343625 ZFS RBAC integration is incomplete


# 898:64b2a371a6bd 12-Nov-2005 kais

PSARC/2005/625 Greyhound - Solaris Kernel SSL proxy
4931229 Kernel-level SSL proxy


# 862:12c6677a0383 07-Nov-2005 vikram

6315667 bootadm complains when running init under pfexec


# 789:b348f31ed315 31-Oct-2005 ahrens

PSARC 2002/240 ZFS
6338653 Integrate ZFS
PSARC 2004/652 - DKIOCFLUSH
5096886 Write caching disks need mechanism to flush cache to physical media


# 0:68f95e015346 14-Jun-2005 stevel@tonic-gate

OpenSolaris Launch